Data Loss Prevention Endpoint (DLPe) - Authentication Bypass vulnerability

CVE-2018-6689

7HIGH

Key Information

Vendor
Mcafee
Status
Data Loss Prevention Endpoint (dlpe)
Vendor
CVE Published:
3 October 2018

Summary

Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditions.

Affected Version(s)

Data Loss Prevention Endpoint (DLPe) < 10.0.0*

Data Loss Prevention Endpoint (DLPe) >= 10.0.510*

Data Loss Prevention Endpoint (DLPe) < 11.0.0*

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

McAfee credits Lockheed Martin Red Team for reporting this flaw.
.