ESConfig Tool able to edit configuration for newer version
CVE-2020-7251

5MEDIUM

Key Information:

Vendor
Mcafee, Llc
Status
Mcafee Endpoint Security (ens)
Vendor
CVE Published:
14 February 2020

Summary

Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from older versions of ENS.

Affected Version(s)

Mcafee Endpoint Security (ENS) 10.6.x < 10.6.1 February 2020 update

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.