First published: Fri Aug 29 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in the User Management module in McAfee Network Security Manager (NSM) before 6.1.15.39 7.1.5.x before 7.1.5.15, 7.1.15.x before 7.1.15.7, 7.5.x before 7.5.5.9, and 8.x before 8.1.7.3 allows remote attackers to hijack the authentication of users for requests that modify user accounts via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Network Security Manager | >=6.1.15<6.1.15.39 | |
McAfee Network Security Manager | >=7.1.5<7.1.5.15 | |
McAfee Network Security Manager | >=7.1.15<7.1.15.7 | |
McAfee Network Security Manager | >=7.5.5<7.5.5.9 | |
McAfee Network Security Manager | >=8.1.7<8.1.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2390 has a moderate severity rating due to its potential for enabling unauthorized actions by remote attackers.
To fix CVE-2014-2390, upgrade McAfee Network Security Manager to version 6.1.15.39 or later, 7.1.5.15 or later, 7.1.15.7 or later, 7.5.5.9 or later, or 8.1.7.3 or later.
CVE-2014-2390 affects McAfee Network Security Manager versions prior to 6.1.15.39, 7.1.5.15, 7.1.15.7, 7.5.5.9, and 8.1.7.3.
CVE-2014-2390 is a Cross-site request forgery (CSRF) vulnerability specifically in the User Management module of McAfee Network Security Manager.
Yes, CVE-2014-2390 can allow remote attackers to hijack user authentication and perform unauthorized actions.