First published: Thu Nov 14 2019(Updated: )
Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Data Loss Prevention | >=11.0.0<=11.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-3640.
The title of this vulnerability is 'Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0'.
The affected software version range is from version 11.0.0 to 11.4.0 of McAfee Data Loss Prevention.
Remote attackers with access to the network can exploit this vulnerability to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity.
You can find more information about this vulnerability on the McAfee Knowledge Center: [link](https://kc.mcafee.com/corporate/index?page=content&id=SB10298).