Mcafee Llc Mcafee Advanced Threat Defense vulnerabilities
4 known vulnerabilities affecting mcafee_llc/mcafee_advanced_threat_defense.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2020-7269MEDIUMCVSS 4.3≥ unspecified, < 4.12.22021-04-15
CVE-2020-7269 [MEDIUM] CWE-200 CVE-2020-7269: Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior
Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted information via a carefully crafted HTTP request parameter. The risk is partially mitigated if your ATD instances are deployed as recommended with no direct access from the Inter
cvelistv5nvd
CVE-2020-7270MEDIUMCVSS 4.3≥ unspecified, < 4.12.22021-04-15
CVE-2020-7270 [MEDIUM] CWE-200 CVE-2020-7270: Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior
Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted information via a carefully crafted HTTP request parameter. The risk is partially mitigated if your ATD instances are deployed as recommended with no direct access from the Inter
cvelistv5nvd
CVE-2020-7262MEDIUMCVSS 5.5≥ 4.x, < 4.10.02020-06-22
CVE-2020-7262 [MEDIUM] CWE-200 CVE-2020-7262: Improper Access Control vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.10.0 allows
Improper Access Control vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.10.0 allows local users to view sensitive files via a carefully crafted HTTP request parameter.
cvelistv5nvd
CVE-2020-7254HIGHCVSS 7.8≥ 4.x, < 4.8.22020-03-12
CVE-2020-7254 [HIGH] CWE-264 CVE-2020-7254: Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (
Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improper access controls on the sudo command.
cvelistv5nvd