VulnerabilityModified
CVE-2017-3933
Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via a cross site request forgery attack.
MEDIUM 5.4EPSS 0.64%
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via a cross site request forgery attack.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mcafee/network data loss prevention
- Source
- secure@intel.com
References
- http://www.securityfocus.com/bid/101628Third Party Advisory, VDB Entry
- https://kc.mcafee.com/corporate/index?page=content&id=SB10198Patch, Vendor Advisory
- http://www.securityfocus.com/bid/101628Third Party Advisory, VDB Entry
- https://kc.mcafee.com/corporate/index?page=content&id=SB10198Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.