First published: Tue Mar 26 2019(Updated: )
Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrators to view configuration information in plain text format via the GUI or GUI terminal commands.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Network Security Manager | >=9.1<9.1.7.75 | |
McAfee Network Security Manager | >=9.2<9.2.7.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3606 is a Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2.
CVE-2019-3606 has a severity rating of 4.1 (High).
CVE-2019-3606 allows administrators to view configuration information in plain text format via the GUI or GUI terminal commands in McAfee Network Security Manager (NSM) versions 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2.
To fix CVE-2019-3606, users should update McAfee Network Security Manager (NSM) to version 9.1.7.75 (Update 4) or later, or version 9.2.7.31 Update2 or later.
More information about CVE-2019-3606 can be found at the following references: http://www.securityfocus.com/bid/107613, https://kc.mcafee.com/corporate/index?page=content&id=SB10274