6.5
CVE-2020-7308
- EPSS 0.09%
- Veröffentlicht 15.04.2021 08:15:14
- Zuletzt bearbeitet 21.11.2024 05:37:02
- Quelle trellixpsirt@trellix.com
- Teams Watchlist Login
- Unerledigt Login
Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI over DNS. By gaining control of an intermediate DNS server or altering the network DNS configuration, it is possible for an attacker to intercept requests and send their own responses.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Endpoint Security SwPlatformwindows Version <= 10.6.1
Mcafee ≫ Endpoint Security Version10.6.1 Update- SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.1 Updateapril_2020 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.1 Updatedecember_2018 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.1 Updatedecember_2019 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.1 Updatefebruary_2019 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.1 Updatefebruary_2020 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.1 Updatejuly_2019 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.1 Updatejuly_2020 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.1 Updatemay_2019 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.1 Updatenovember_2018 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.1 Updatenovember_2020 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.1 Updateoctober_2019 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.6.1 Updateseptember_2020 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.7.0 Updatefebruary_2020 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.7.0 Updatejuly_2020 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.7.0 Updatenovember_2020 SwPlatformwindows
Mcafee ≫ Endpoint Security Version10.7.0 Updateseptember_2020 SwPlatformwindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.09% | 0.232 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
trellixpsirt@trellix.com | 4.8 | 2.2 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.