CVE-2017-3972 — Sensitive Information Exposure in Network Security Management
Severity
9.8CRITICALNVD
EPSS
0.9%
top 25.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 3
Latest updateMay 13
Description
Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to execute arbitrary code via the server banner leaking potentially sensitive or security relevant information.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages2 packages
🔴Vulnerability Details
1GHSA▶
GHSA-8983-36qp-wh5w: Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8↗2022-05-13