First published: Thu Aug 13 2020(Updated: )
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing plain text credentials.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Data Loss Prevention | >=11.3.0<11.3.28 | |
Mcafee Data Loss Prevention | >=11.4.0<11.4.200 | |
Mcafee Data Loss Prevention | >=11.5.0<11.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-7307.
The affected software is McAfee Data Loss Prevention (DLP) for Mac versions prior to 11.5.2.
The severity of CVE-2020-7307 is medium, with a CVSS score of 5.2.
Local users can exploit this vulnerability by gaining access to the RiskDB username and password via unprotected log files containing plain text credentials.
Yes, McAfee Data Loss Prevention (DLP) for Mac version 11.5.2 or later addresses this vulnerability.