6.5

CVE-2020-7308

Transmission of data in clear text by McAfee ENS

Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI over DNS. By gaining control of an intermediate DNS server or altering the network DNS configuration, it is possible for an attacker to intercept requests and send their own responses.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Endpoint Security SwPlatform windows Version <= 10.6.1
Mcafee ≫ Endpoint Security Version 10.6.1 Update - SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.6.1 Update april_2020 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.6.1 Update december_2018 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.6.1 Update december_2019 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.6.1 Update february_2019 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.6.1 Update february_2020 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.6.1 Update july_2019 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.6.1 Update july_2020 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.6.1 Update may_2019 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.6.1 Update november_2018 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.6.1 Update november_2020 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.6.1 Update october_2019 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.6.1 Update september_2020 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.7.0 Update february_2020 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.7.0 Update july_2020 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.7.0 Update november_2020 SwPlatform windows
Mcafee ≫ Endpoint Security Version 10.7.0 Update september_2020 SwPlatform windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.393
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
Trellix 4.8 2.2 2.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

https://kc.mcafee.com/corporate/index?page=content&id=SB10354
Vendor Advisory
Broken Link