CVE-2017-3934: Infoleak
Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-in-the-middle attackers to expose confidential data via read files on the webserver.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3934?
CVE-2017-3934 has a medium severity rating due to its potential for man-in-the-middle attacks.
How do I fix CVE-2017-3934?
To fix CVE-2017-3934, ensure that HTTP Strict Transport Security is properly configured on the McAfee Network Data Loss Prevention server.
What versions are affected by CVE-2017-3934?
CVE-2017-3934 affects McAfee Network Data Loss Prevention versions up to and including 9.3.0.
What impact does CVE-2017-3934 have on data security?
CVE-2017-3934 can lead to compromised data confidentiality due to the lack of HTTP Strict Transport Security.
Can CVE-2017-3934 be exploited remotely?
Yes, CVE-2017-3934 can be exploited remotely by an attacker who can perform man-in-the-middle attacks.