CVE-2020-7336: Network Security Management (NSM) - Cross Site Request Forgery vulnerability
Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7336?
CVE-2020-7336 is a Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 that may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.
How does CVE-2020-7336 affect McAfee Network Security Management (NSM)?
CVE-2020-7336 affects McAfee Network Security Management (NSM) prior to version 10.1.7.35 and NSM 9.x prior to version 9.2.9.55.
What is the severity of CVE-2020-7336?
The severity of CVE-2020-7336 is medium with a severity value of 6.5.
How can an attacker exploit CVE-2020-7336?
An attacker can exploit CVE-2020-7336 by sending a carefully crafted HTTP request to change the configuration of the Network Security Manager.
How can I fix CVE-2020-7336?
To fix CVE-2020-7336, update McAfee Network Security Management (NSM) to version 10.1.7.35 or higher for NSM 10.x, and version 9.2.9.55 or higher for NSM 9.x.