← Back

CVE-2017-3965

nvd nist
Published: Apr 4, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs.

Affected (1)

1 product
Network Security Manager
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 8.2.7.42.2

References (2)

Timeline

No history available yet.