CVE-2020-7329: Server-Side Request Forgery (SSRF) in MVISION Endpoint ePO extension
Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2020-7329.
What software is affected by this vulnerability?
McAfee MVISION Endpoint prior to version 20.11 is affected by this vulnerability.
What is the severity level of CVE-2020-7329?
The severity level of CVE-2020-7329 is high with a CVSS score of 7.2.
What is the description of this vulnerability?
CVE-2020-7329 is a server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11, allowing remote attackers to trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.
How can I fix this vulnerability?
Upgrade to version 20.11 or later of McAfee MVISION Endpoint to mitigate this vulnerability.