CVE-2019-3599: McAfee Agent update fixes an Information Disclosure vulnerability
Published Feb 28, 2019
·Updated
Information Disclosure vulnerability in Remote logging (which is disabled by default) in McAfee Agent (MA) 5.x allows remote unauthenticated users to access sensitive information via remote logging when it is enabled.
Affected Software
3 affected components
McAfee Agent>=5.0.0<=5.0.6
McAfee Agent>=5.5.0<=5.5.2
McAfee Agent=5.6.0
Event History
Feb 28, 2019
CVE Published
03:29 PM
Data Sourced
via NVD·03:29 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-3599?
CVE-2019-3599 is an Information Disclosure vulnerability in Remote logging in McAfee Agent (MA) 5.x.
2
How does CVE-2019-3599 affect McAfee Agent?
CVE-2019-3599 allows remote unauthenticated users to access sensitive information via remote logging when it is enabled.
3
Is remote logging enabled by default in McAfee Agent?
No, remote logging is disabled by default in McAfee Agent.
4
Which versions of McAfee Agent are affected by CVE-2019-3599?
McAfee Agent versions 5.0.0 to 5.0.6, 5.5.0 to 5.5.2, and 5.6.0 are affected by CVE-2019-3599.
5
How severe is CVE-2019-3599?
CVE-2019-3599 has a severity score of 7.5 (high).