CVE-2017-4055Missing Authentication for Critical Function in Advanced Threat Defense

Severity
7.5HIGHNVD
EPSS
0.6%
top 29.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12
Latest updateMay 17

Description

Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to bypass ATD detection via loose enforcement of authentication and authorization.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5mcafee/advanced_threat_defense4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-48vg-r6v2-75w4: Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 32022-05-17
CVEList
CVE-2017-4055: Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 32017-07-12

📋Vendor Advisories

2
Microsoft
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string a different vulnerability than CVE-2016-4055.2018-03-13
Red Hat
nodejs-moment: Regular expression denial of service2017-09-08

💬Community

1
Bugzilla
CVE-2017-18214 nodejs-moment: Regular expression denial of service2018-03-08
CVE-2017-4055 — Mcafee vulnerability | cvebase