CVE-2017-3969: SB10192 - Network Security Management (NSM) - Abuse of communication channels vulnerability
Published Apr 4, 2018
·Updated
Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle attackers to decrypt messages via an inadequate implementation of SSL.
Affected Software
1 affected component
McAfee Network Security Manager<8.2.7.42.2
Event History
Apr 4, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-3969?
The severity of CVE-2017-3969 is high.
2
What does CVE-2017-3969 affect?
CVE-2017-3969 affects McAfee Network Security Management (NSM) before 8.2.7.42.2.
3
How can an attacker exploit CVE-2017-3969?
An attacker can exploit CVE-2017-3969 by performing a man-in-the-middle attack to decrypt messages due to an inadequate implementation of SSL.
4
How can I fix CVE-2017-3969?
To fix CVE-2017-3969, update McAfee Network Security Management (NSM) to version 8.2.7.42.2 or higher.
5
Where can I find more information about CVE-2017-3969?
You can find more information about CVE-2017-3969 [here](https://kc.mcafee.com/corporate/index?page=content&id=SB10192).