nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-34405 CVE-2024-34405
CRITICAL
Record summary
CVE-2024-34405 has a selected CVSS score of 9.1 (critical).
Description
Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to launch an arbitrary URL within the app.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 12, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
antivirus_vpn_for_androidBrowse mcafee / antivirus_vpn_for_androidDefault status: unknown | CVE List | Before 8.3.0 | affected |
References
3mcafee.com
https://www.mcafee.com/en-us/consumer-corporate/mcafee-labs/product-security-bulletins.html mcafee.com
https://www.mcafee.com/support?page=shell&shell=article-view&articleId=000002403