CVE-2017-3966 — Insufficient Session Expiration in Network Security Management
Severity
6.3MEDIUMNVD
EPSS
0.2%
top 55.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 4
Latest updateMay 13
Description
Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to exploit or harm a user's browser via reusing the exposed session token in the application URL.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4
Affected Packages2 packages
🔴Vulnerability Details
1GHSA▶
GHSA-p7mx-frqj-j9hq: Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAfee Network Security Management↗2022-05-13