CVE-2017-4054
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
12/07/2017
Last modified:
20/04/2025
Description
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to execute a command of their choice via a crafted HTTP request parameter.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mcafee:advanced_threat_defense:3.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mcafee:advanced_threat_defense:3.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mcafee:advanced_threat_defense:3.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mcafee:advanced_threat_defense:3.10:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



