CVE-2017-3966: SB10192 - Network Security Management (NSM) - Exploitation of session variables, resource IDs and other trusted credentials vulnerability
Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to exploit or harm a user's browser via reusing the exposed session token in the application URL.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-3966?
CVE-2017-3966 is a vulnerability in McAfee Network Security Management (NSM) that allows remote attackers to exploit or harm a user's browser by reusing the exposed session token in the application URL.
How does CVE-2017-3966 affect McAfee Network Security Manager?
CVE-2017-3966 affects McAfee Network Security Manager version up to 8.2.7.42.2.
What is the severity of CVE-2017-3966?
CVE-2017-3966 has a severity rating of 6.3 (Medium).
How can remote attackers exploit CVE-2017-3966?
Remote attackers can exploit CVE-2017-3966 by reusing the exposed session token in the application URL.
Is there a fix for CVE-2017-3966?
Yes, updating McAfee Network Security Manager to version 8.2.7.42.2 or above will fix CVE-2017-3966.