First published: Mon Feb 13 2017(Updated: )
Unvalidated parameter vulnerability in the remote log viewing capability in Intel Security McAfee Agent 5.0.x versions prior to 5.0.4.449 allows remote attackers to pass unexpected input parameters via a URL that was not completely validated.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Agent | =5.0.0 | |
McAfee Agent | =5.0.1 | |
McAfee Agent | =5.0.2 | |
McAfee Agent | =5.0.3 | |
McAfee Agent | =5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3896 has a medium severity level due to its potential for remote code execution via unvalidated parameters.
To fix CVE-2017-3896, upgrade your McAfee Agent to version 5.0.4.449 or later.
CVE-2017-3896 affects Intel Security McAfee Agent versions 5.0.0 through 5.0.3.
CVE-2017-3896 is an unvalidated parameter vulnerability that can be exploited through URL manipulation.
Yes, CVE-2017-3896 can be exploited remotely by attackers sending crafted requests.