CVE-2020-7332: Cross-Site Request Forgery (CSRF) in firewall ePO extension of McAfee Endpoint Security (ENS)
Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows an attacker to execute arbitrary HTML code due to incorrect security configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7332?
The severity of CVE-2020-7332 is high with a severity value of 8.8.
Which software versions are affected by CVE-2020-7332?
McAfee Endpoint Security (ENS) versions prior to 10.7.0 November 2020 Update are affected by CVE-2020-7332.
How can an attacker exploit CVE-2020-7332?
An attacker can exploit CVE-2020-7332 by executing arbitrary HTML code due to incorrect security configuration.
How can I fix CVE-2020-7332?
To fix CVE-2020-7332, update McAfee Endpoint Security (ENS) to version 10.7.0 November 2020 Update or later.
Where can I find more information about CVE-2020-7332?
More information about CVE-2020-7332 can be found in the [McAfee Knowledge Center](https://kc.mcafee.com/corporate/index?page=content&id=SB10335).