6.7
CVE-2020-7263
- EPSS 0.04%
- Veröffentlicht 01.04.2020 07:15:13
- Zuletzt bearbeitet 21.11.2024 05:36:57
- Quelle trellixpsirt@trellix.com
- Teams Watchlist Login
- Unerledigt Login
Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Endpoint Security Version10.5.0 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.5.1 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.5.2 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.5.3 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.5.4 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.5.5 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.0 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.1 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.7.0 SwPlatformwindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.104 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
trellixpsirt@trellix.com | 6.5 | 0.6 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.