CVE-2020-7329

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
11/11/2020
Last modified:
16/11/2023

Description

Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mcafee:mvision_endpoint:*:*:*:*:*:*:*:* 20.11 (excluding)


References to Advisories, Solutions, and Tools