First published: Tue Oct 31 2017(Updated: )
Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-in-the-middle attackers to expose confidential data via read files on the webserver.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Network Data Loss Prevention | <=9.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3934 has a medium severity rating due to its potential for man-in-the-middle attacks.
To fix CVE-2017-3934, ensure that HTTP Strict Transport Security is properly configured on the McAfee Network Data Loss Prevention server.
CVE-2017-3934 affects McAfee Network Data Loss Prevention versions up to and including 9.3.0.
CVE-2017-3934 can lead to compromised data confidentiality due to the lack of HTTP Strict Transport Security.
Yes, CVE-2017-3934 can be exploited remotely by an attacker who can perform man-in-the-middle attacks.