7.8
CVE-2017-3912
- EPSS 0.03%
- Veröffentlicht 18.09.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:26:21
- Quelle trellixpsirt@trellix.com
- CVE-Watchlists
- Unerledigt
McAfee Application Control and Change Control (MACC) - password management security feature bypass (SFB) leading to an authentication bypass
Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Application And Change Control Version6.2.0
Mcafee ≫ Application And Change Control Version7.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.089 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
| trellixpsirt@trellix.com | 4.4 | 0.8 | 3.6 |
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
CWE-274 Improper Handling of Insufficient Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.