ESConfig Tool able to edit configuration for newer version
CVE-2020-7251
5MEDIUM
Key Information:
- Vendor
- Mcafee, Llc
- Status
- Mcafee Endpoint Security (ens)
- Vendor
- CVE Published:
- 14 February 2020
Summary
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from older versions of ENS.
Affected Version(s)
Mcafee Endpoint Security (ENS) 10.6.x < 10.6.1 February 2020 update
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved