Improper Verification of Cryptographic Signature by McAfee Agent
CVE-2022-1257
6.1MEDIUM
Key Information:
- Vendor
- Mcafee,llc
- Status
- Mcafee Agent
- Vendor
- CVE Published:
- 14 April 2022
Summary
Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information has been moved to encrypted database files.
Affected Version(s)
McAfee Agent < 5.7.6
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved