CVE-2020-7305: DLP ePO extension - Privilege escalation
Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to create new rule sets via incorrect validation of user credentials.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7305?
CVE-2020-7305 is a privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3.
How does CVE-2020-7305 affect McAfee Data Loss Prevention?
CVE-2020-7305 allows a low privileged remote attacker to create new rule sets via incorrect validation of user credentials in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3.
What is the severity of CVE-2020-7305?
The severity of CVE-2020-7305 is rated as medium, with a severity value of 6.5.
What versions of McAfee Data Loss Prevention are affected by CVE-2020-7305?
Versions of McAfee Data Loss Prevention prior to 11.5.3 are affected by CVE-2020-7305.
How can I fix CVE-2020-7305?
To fix CVE-2020-7305, it is recommended to update McAfee Data Loss Prevention to version 11.5.3 or later.