First published: Tue Jan 05 2021(Updated: )
Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Network Security Management | >=9.0<9.2.9.55 | |
McAfee Network Security Management | >=10.0<10.1.7.35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7336 is a Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 that may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.
CVE-2020-7336 affects McAfee Network Security Management (NSM) prior to version 10.1.7.35 and NSM 9.x prior to version 9.2.9.55.
The severity of CVE-2020-7336 is medium with a severity value of 6.5.
An attacker can exploit CVE-2020-7336 by sending a carefully crafted HTTP request to change the configuration of the Network Security Manager.
To fix CVE-2020-7336, update McAfee Network Security Management (NSM) to version 10.1.7.35 or higher for NSM 10.x, and version 9.2.9.55 or higher for NSM 9.x.