First published: Wed Nov 11 2020(Updated: )
Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee MVISION Endpoint | <20.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-7329.
McAfee MVISION Endpoint prior to version 20.11 is affected by this vulnerability.
The severity level of CVE-2020-7329 is high with a CVSS score of 7.2.
CVE-2020-7329 is a server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11, allowing remote attackers to trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.
Upgrade to version 20.11 or later of McAfee MVISION Endpoint to mitigate this vulnerability.