CVE-2019-3599

Severity
7.5HIGH
EPSS
0.3%
top 45.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 28
Latest updateMay 24

Description

Information Disclosure vulnerability in Remote logging (which is disabled by default) in McAfee Agent (MA) 5.x allows remote unauthenticated users to access sensitive information via remote logging when it is enabled.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5mcafee,_llc/mcafee_agent_(ma)5.x5.6.0 HF1
NVDmcafee/agent5.0.05.0.6+2

🔴Vulnerability Details

3
GHSA
Withdrawn Advisory: Fat Free CRM Cross-site Scripting vulnerability2022-05-24
GHSA
GHSA-gj5x-6xwx-4g9m: Information Disclosure vulnerability in Remote logging (which is disabled by default) in McAfee Agent (MA) 52022-05-13
CVEList
McAfee Agent update fixes an Information Disclosure vulnerability2019-02-28