Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) Prior to 9.1 Update 5 allows an authenticated administrator to embed an XSS in the administrator interface via a specially crafted custom rule containing HTML.

  • Published Date: Wednesday 15th of May 2019 12:29:00 PM
  • Modified Date: Wednesday 15th of May 2019 02:36:22 PM
    • Network Access Vector: The attacker does not require local network access or local access.
    • Authentication Vector: One instance of authentication is required to access and exploit the vulnerability.
    • Complexity Vector: One instance of complexity is required to access and exploit the vulnerability.
    • Availability Impact: There is no impact to the availability of the system.
    • Integrity Impact: Modification of some system files is posible.
    • Confidentiality Impact: There is none information disclosure.
    • CVSS Score: 3.5
    • Common Platform Enumeration (CPE) Dictionary
      • cpe:2.3:a:mcafee:network_security_manager:6.1.15.38
      • cpe:2.3:a:mcafee:network_security_manager:6.1.15.39
      • cpe:2.3:a:mcafee:network_security_manager:7.1.5.14
      • cpe:2.3:a:mcafee:network_security_manager:7.1.5.15
      • cpe:2.3:a:mcafee:network_security_manager:7.1.15.6
      • cpe:2.3:a:mcafee:network_security_manager:7.1.15.7
      • cpe:2.3:a:mcafee:network_security_manager:7.5.5.8
      • cpe:2.3:a:mcafee:network_security_manager:7.5.5.9
      • cpe:2.3:a:mcafee:network_security_manager:8.1.7.2
      • cpe:2.3:a:mcafee:network_security_manager:8.1.7.3
      • cpe:2.3:a:mcafee:network_security_manager:9.1
      • cpe:2.3:a:mcafee:network_security_manager:9.1:update_1
      • cpe:2.3:a:mcafee:network_security_manager:9.1:update_2
      • cpe:2.3:a:mcafee:network_security_manager:9.1:update_3
      • cpe:2.3:a:mcafee:network_security_manager:9.1:update_4
    • Reference:

    Download Mageni's Vulnerability Scanning Platform.

    No credit card is required to download the Free Edition. Register now.