CVE-2017-3972Sensitive Information Exposure in Network Security Management

Severity
9.8CRITICALNVD
EPSS
0.9%
top 25.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 3
Latest updateMay 13

Description

Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to execute arbitrary code via the server banner leaking potentially sensitive or security relevant information.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5mcafee/network_security_management8.28.2.7.42.2

🔴Vulnerability Details

1
GHSA
GHSA-8983-36qp-wh5w: Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before 82022-05-13