First published: Thu Apr 15 2021(Updated: )
Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted information via a carefully crafted HTTP request parameter. The risk is partially mitigated if your ATD instances are deployed as recommended with no direct access from the Internet to them.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Advanced Threat Defense | <4.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7270 is a vulnerability in the web interface of McAfee Advanced Threat Defense (ATD) prior to 4.12.2 that allows remote authenticated users to view sensitive unencrypted information.
Remote authenticated users can exploit CVE-2020-7270 by sending a carefully crafted HTTP request parameter.
The risk of CVE-2020-7270 is the exposure of sensitive unencrypted information.
You can partially mitigate the risk of CVE-2020-7270 by ensuring that your ATD instances are deployed properly.
You can find more information about CVE-2020-7270 at the following link: [McAfee Knowledge Center](https://kc.mcafee.com/corporate/index?page=content&id=SB10336)