First published: Wed Apr 04 2018(Updated: )
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Network Security Manager | <8.2.7.42.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3965 is a Cross-Site Request Forgery (CSRF) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2.
The severity of CVE-2017-3965 is rated as high with a severity value of 8.8.
CVE-2017-3965 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted requests.
McAfee Network Security Manager versions before 8.2.7.42.2 are affected by CVE-2017-3965.
To fix CVE-2017-3965, it is recommended to upgrade McAfee Network Security Manager to version 8.2.7.42.2 or newer.