CVE-2019-3602: Cross site scripting vulnerability in McAfee NSM impacting authenticated users
Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) Prior to 9.1 Update 5 allows an authenticated administrator to embed an XSS in the administrator interface via a specially crafted custom rule containing HTML.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3602?
The severity of CVE-2019-3602 is medium with a CVSS score of 4.8.
How does CVE-2019-3602 affect McAfee Network Security Manager (NSM)?
CVE-2019-3602 affects McAfee Network Security Manager (NSM) versions prior to 9.1 Update 5.
What is the impact of CVE-2019-3602?
CVE-2019-3602 allows an authenticated administrator to embed an XSS in the administrator interface of McAfee Network Security Manager (NSM) via a specially crafted custom rule containing HTML.
How can I fix the Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) (CVE-2019-3602)?
To fix CVE-2019-3602, update McAfee Network Security Manager (NSM) to version 9.1 Update 5 or later.
Where can I find more information about CVE-2019-3602?
You can find more information about CVE-2019-3602 at the following links: - [http://www.securityfocus.com/bid/108400](http://www.securityfocus.com/bid/108400) - [https://kc.mcafee.com/corporate/index?page=content&id=SB10281](https://kc.mcafee.com/corporate/index?page=content&id=SB10281)