6.5

CVE-2020-7308

Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI over DNS. By gaining control of an intermediate DNS server or altering the network DNS configuration, it is possible for an attacker to intercept requests and send their own responses.

Data is provided by the National Vulnerability Database (NVD)
McafeeEndpoint Security SwPlatformwindows Version <= 10.6.1
McafeeEndpoint Security Version10.6.1 Update- SwPlatformwindows
McafeeEndpoint Security Version10.6.1 Updateapril_2020 SwPlatformwindows
McafeeEndpoint Security Version10.6.1 Updatedecember_2018 SwPlatformwindows
McafeeEndpoint Security Version10.6.1 Updatedecember_2019 SwPlatformwindows
McafeeEndpoint Security Version10.6.1 Updatefebruary_2019 SwPlatformwindows
McafeeEndpoint Security Version10.6.1 Updatefebruary_2020 SwPlatformwindows
McafeeEndpoint Security Version10.6.1 Updatejuly_2019 SwPlatformwindows
McafeeEndpoint Security Version10.6.1 Updatejuly_2020 SwPlatformwindows
McafeeEndpoint Security Version10.6.1 Updatemay_2019 SwPlatformwindows
McafeeEndpoint Security Version10.6.1 Updatenovember_2018 SwPlatformwindows
McafeeEndpoint Security Version10.6.1 Updatenovember_2020 SwPlatformwindows
McafeeEndpoint Security Version10.6.1 Updateoctober_2019 SwPlatformwindows
McafeeEndpoint Security Version10.6.1 Updateseptember_2020 SwPlatformwindows
McafeeEndpoint Security Version10.7.0 Updatefebruary_2020 SwPlatformwindows
McafeeEndpoint Security Version10.7.0 Updatejuly_2020 SwPlatformwindows
McafeeEndpoint Security Version10.7.0 Updatenovember_2020 SwPlatformwindows
McafeeEndpoint Security Version10.7.0 Updateseptember_2020 SwPlatformwindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.232
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
trellixpsirt@trellix.com 4.8 2.2 2.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.