CVE-2014-8524Sensitive Information Exposure in Network Data Loss Prevention

Severity
5.0MEDIUMNVD
EPSS
0.4%
top 39.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 29
Latest updateMay 17

Description

McAfee Network Data Loss Prevention (NDLP) before 9.3 does not disable the autocomplete setting for the password and other fields, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

1
GHSA
GHSA-8fwv-p5f2-v3rj: McAfee Network Data Loss Prevention (NDLP) before 92022-05-17