CVE-2019-3670: Remote Code Execution vulnerability
Published Feb 24, 2020
·Updated
Remote Code Execution vulnerability in the web interface in McAfee Web Advisor (WA) 8.0.34745 and earlier allows remote unauthenticated attacker to execute arbitrary code via a cross site scripting attack.
Affected Software
2 affected components
McAfee Web Advisor Chrome<=8.0.34745
McAfee Web Advisor Firefox<=8.0.0.34239
Remediation
Event History
Feb 24, 2020
CVE Published
via MITRE·10:10 AM
Data Sourced
via MITRE·10:10 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-3670?
CVE-2019-3670 is a Remote Code Execution vulnerability in the web interface of McAfee Web Advisor (WA) 8.0.34745 and earlier.
2
How severe is CVE-2019-3670?
CVE-2019-3670 has a severity rating of 6.1 (high).
3
What is the affected software for CVE-2019-3670?
The affected software for CVE-2019-3670 is McAfee Web Advisor versions 8.0.34745 and earlier for Chrome and Firefox.
4
How can an attacker exploit CVE-2019-3670?
An attacker can exploit CVE-2019-3670 by executing arbitrary code via a cross-site scripting attack on the web interface of McAfee Web Advisor.
5
Is there a fix for CVE-2019-3670?
Yes, a fix for CVE-2019-3670 is available. Please refer to the reference link for more information.