CVE-2019-3660

HIGH

McAfee ATD <4.8 - Command Injection

Title source: llm
STIX 2.1

Description

Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute commands on the server remotely via carefully constructed HTTP requests.

References (1)

Core 1
Core References

Scores

CVSS v3 8.4
EPSS 0.0073
EPSS Percentile 72.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H

Details

Status published
Products (1)
mcafee/advanced_threat_defense < 4.8
Published Nov 13, 2019
Tracked Since Feb 18, 2026