Network Security Management (NSM) - Cross Site Request Forgery vulnerability
CVE-2020-7336
6.6MEDIUM
Key Information
- Vendor
- Mcafee
- Status
- Network Security Management (nsm)
- Vendor
- CVE Published:
- 5 January 2021
Summary
Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.
Affected Version(s)
Network Security Management (NSM) < 10.1.7.35
Network Security Management (NSM) < 9.2.9.55
References
CVSS V3.1
Score:
6.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database