CVE-2019-3640: Data Loss Prevention - Unprotected Transport of Credentials
Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-3640.
What is the title of this vulnerability?
The title of this vulnerability is 'Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0'.
What is the affected software version range?
The affected software version range is from version 11.0.0 to 11.4.0 of McAfee Data Loss Prevention.
How can remote attackers exploit this vulnerability?
Remote attackers with access to the network can exploit this vulnerability to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the McAfee Knowledge Center: [link](https://kc.mcafee.com/corporate/index?page=content&id=SB10298).