CVE-2017-3965

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
04/04/2018
Last modified:
07/11/2023

Description

Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:* 8.2.7.42.2 (excluding)


References to Advisories, Solutions, and Tools