CVE-2017-4054: Command Injection
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to execute a command of their choice via a crafted HTTP request parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4054?
CVE-2017-4054 has a medium severity rating due to its potential for command execution by authenticated users.
How do I fix CVE-2017-4054?
To fix CVE-2017-4054, update your McAfee Advanced Threat Defense software to the latest version recommended by McAfee.
Who is affected by CVE-2017-4054?
CVE-2017-4054 affects remote authenticated users of McAfee Advanced Threat Defense versions 3.4, 3.6, 3.8, and 3.10.
What type of vulnerability is CVE-2017-4054?
CVE-2017-4054 is a command injection vulnerability that allows execution of arbitrary commands.
Is CVE-2017-4054 being actively exploited?
There have been reports of CVE-2017-4054 being targeted in the wild, making it imperative to apply patches promptly.