CVE-2020-7251: ESConfig Tool able to edit configuration for newer version
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from older versions of ENS.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
McAfee Endpoint Security (ENS) Configuration Toolto a version that resolves this vulnerability.Fixed in 10.6.1
Event History
Frequently Asked Questions
What is CVE-2020-7251?
CVE-2020-7251 is an improper access control vulnerability in the Configuration Tool in McAfee Endpoint Security (ENS) prior to version 10.6.1 February 2020 Update.
How does CVE-2020-7251 affect McAfee Endpoint Security?
CVE-2020-7251 allows local users to disable security features by unauthorized use of the Configuration Tool from older versions of ENS.
What is the severity of CVE-2020-7251?
CVE-2020-7251 has a severity rating of medium with a score of 5.5.
How can I fix CVE-2020-7251?
To fix CVE-2020-7251, update McAfee Endpoint Security to version 10.6.1 February 2020 Update or later.
Where can I find more information about CVE-2020-7251?
For more information about CVE-2020-7251, you can visit the official McAfee knowledge base at the following link: https://kc.mcafee.com/corporate/index?page=content&id=SB10299