CVE-2017-3961: SB10192 - Network Security Management (NSM) - Cross-Site Scripting (XSS) vulnerability
Published May 25, 2018
·Updated
Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via crafted user input of attributes.
Affected Software
1 affected component
McAfee Network Security Manager<8.2.7.42.2
Event History
May 25, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-3961.
2
What is the severity rating of CVE-2017-3961?
CVE-2017-3961 has a severity rating of medium (5.4).
3
What is the impacted software for CVE-2017-3961?
The impacted software for CVE-2017-3961 is McAfee Network Security Manager version up to 8.2.7.42.2.
4
What is the CWE category for CVE-2017-3961?
The CWE category for CVE-2017-3961 is CWE-79 (Cross-Site Scripting).
5
How can I fix the Cross-Site Scripting (XSS) vulnerability in McAfee Network Security Manager?
To fix the Cross-Site Scripting (XSS) vulnerability in McAfee Network Security Manager, update to version 8.2.7.42.2 or later.