5.5
CVE-2019-3653
- EPSS 0.05%
- Veröffentlicht 09.10.2019 16:15:16
- Zuletzt bearbeitet 21.11.2024 04:42:18
- Quelle trellixpsirt@trellix.com
- Teams Watchlist Login
- Unerledigt Login
Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to gain access to security configuration via unauthorized use of the configuration tool.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Endpoint Security Version >= 10.5.0 <= 10.5.5
Mcafee ≫ Endpoint Security Version >= 10.6.0 < 10.6.1
Mcafee ≫ Endpoint Security Version10.16.1 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.12 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:N/I:P/A:N
|
trellixpsirt@trellix.com | 4.6 | 0.3 | 4.2 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.