SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-7322

Information Disclosure Vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to gain access to sensitive information via incorrectly logging of sensitive information in debug logs.

MEDIUM 4.7EPSS 0.25%

Does this matter?

Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.

Description

Information Disclosure Vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to gain access to sensitive information via incorrectly logging of sensitive information in debug logs.

CVSS 3.1
4.7 MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L
EPSS
0.25% probability · 16th percentile
CISA KEV
Not listed
Weakness
CWE-532
Affected
mcafee/endpoint security
Source
trellixpsirt@trellix.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.