CVE-2017-3968: McAfee Network Security Management (NSM) and Network Data Loss Prevention (NDLP)- Password recovery exploitation vulnerability
Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2017-3968.
What is the severity of CVE-2017-3968?
The severity of CVE-2017-3968 is critical with a score of 9.1.
Which software is affected by CVE-2017-3968?
McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 are affected.
What can an attacker do with this vulnerability?
An attacker can disclose sensitive information or manipulate the database using a crafted authentication cookie.
How can I mitigate CVE-2017-3968?
Upgrade McAfee Network Security Manager to version 8.2.7.42.2 or later and McAfee Network Data Loss Prevention to version 9.3.4.1.5 or later.