CVE-2019-3606: Data leakage when in an MDR pair by McAfee Network Security Manager 9.x
Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrators to view configuration information in plain text format via the GUI or GUI terminal commands.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3606?
CVE-2019-3606 is a Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2.
What is the severity of CVE-2019-3606?
CVE-2019-3606 has a severity rating of 4.1 (High).
How does CVE-2019-3606 affect McAfee Network Security Manager?
CVE-2019-3606 allows administrators to view configuration information in plain text format via the GUI or GUI terminal commands in McAfee Network Security Manager (NSM) versions 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2.
How can I fix CVE-2019-3606?
To fix CVE-2019-3606, users should update McAfee Network Security Manager (NSM) to version 9.1.7.75 (Update 4) or later, or version 9.2.7.31 Update2 or later.
Where can I find more information about CVE-2019-3606?
More information about CVE-2019-3606 can be found at the following references: http://www.securityfocus.com/bid/107613, https://kc.mcafee.com/corporate/index?page=content&id=SB10274