VulnerabilityModified
CVE-2017-3896
Unvalidated parameter vulnerability in the remote log viewing capability in Intel Security McAfee Agent 5.0.x versions prior to 5.0.4.449 allows remote attackers to pass unexpected input parameters via a URL that was not completely validated.
MEDIUM 5.9EPSS 2.47%
Does this matter?
Lower severity and a low EPSS score (2.47%). Track it; it rarely justifies an emergency change on its own.
Description
Unvalidated parameter vulnerability in the remote log viewing capability in Intel Security McAfee Agent 5.0.x versions prior to 5.0.4.449 allows remote attackers to pass unexpected input parameters via a URL that was not completely validated.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.47% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- mcafee/mcafee agent
- Source
- secure@intel.com
References
- http://www.securityfocus.com/bid/95903Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037629
- https://kc.mcafee.com/corporate/index?page=content&id=SB10183Vendor Advisory
- http://www.securityfocus.com/bid/95903Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037629
- https://kc.mcafee.com/corporate/index?page=content&id=SB10183Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.