First published: Thu Aug 13 2020(Updated: )
Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Data Loss Prevention | >=11.3.0<11.3.28 | |
Mcafee Data Loss Prevention | >=11.4.0<11.4.200 | |
Mcafee Data Loss Prevention | >=11.5.0<11.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7302 is a vulnerability that allows authenticated attackers to upload malicious files to the McAfee Data Loss Prevention (DLP) ePO extension prior to version 11.5.3.
CVE-2020-7302 has a severity rating of 6.4 (Medium).
CVE-2020-7302 affects McAfee Data Loss Prevention (DLP) versions 11.3.0 to 11.3.28, 11.4.0 to 11.4.200, and 11.5.0 to 11.5.3.
An authenticated attacker can exploit CVE-2020-7302 by uploading malicious files to the DLP case management section via lack of sanity checking.
Yes, McAfee has released a fix for CVE-2020-7302. It is recommended to update to version 11.5.3 or later of McAfee Data Loss Prevention (DLP) ePO extension.