First published: Thu Nov 12 2020(Updated: )
Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows an attacker to execute arbitrary HTML code due to incorrect security configuration.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Endpoint Security | <10.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-7332 is high with a severity value of 8.8.
McAfee Endpoint Security (ENS) versions prior to 10.7.0 November 2020 Update are affected by CVE-2020-7332.
An attacker can exploit CVE-2020-7332 by executing arbitrary HTML code due to incorrect security configuration.
To fix CVE-2020-7332, update McAfee Endpoint Security (ENS) to version 10.7.0 November 2020 Update or later.
More information about CVE-2020-7332 can be found in the [McAfee Knowledge Center](https://kc.mcafee.com/corporate/index?page=content&id=SB10335).