First published: Thu Feb 28 2019(Updated: )
Buffer Access with Incorrect Length Value in McAfee Agent (MA) 5.x allows remote unauthenticated users to potentially cause a denial of service via specifically crafted UDP packets.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Agent | >=5.0.0<=5.0.6 | |
Mcafee Agent | >=5.5.0<=5.5.2 | |
Mcafee Agent | =5.6.0 | |
>=5.0.0<=5.0.6 | ||
>=5.5.0<=5.5.2 | ||
=5.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3598 refers to a vulnerability in McAfee Agent (MA) 5.x that allows remote unauthenticated users to potentially cause a denial of service.
CVE-2019-3598 has a severity level of 5.3, which is considered medium.
McAfee Agent (MA) versions 5.0.0 to 5.0.6, 5.5.0 to 5.5.2, and 5.6.0 are affected by CVE-2019-3598.
CVE-2019-3598 can be exploited by sending specifically crafted UDP packets to the vulnerable McAfee Agent.
Yes, McAfee has released a patch to fix CVE-2019-3598. It is recommended to update to the latest version of McAfee Agent (MA) to mitigate the vulnerability.