McAfee Network Security Manager 9.1

CPE Details

McAfee Network Security Manager 9.1
9.1
2019-04-04
11h08 +00:00
2019-12-16
16h11 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:mcafee:network_security_manager:9.1:*:*:*:*:*:*:*

Informations

Vendor

mcafee

Product

network_security_manager

Version

9.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-4038 2021-12-09 14h55 +00:00 Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administrator interface via specially crafted custom rules containing HTML. NSM did not correctly sanitize custom rule content in all scenarios.
4.8
Medium
CVE-2020-7256 2020-03-18 20h05 +00:00 Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update allows attackers to unspecified impact via unspecified vectors.
4.8
Medium
CVE-2020-7258 2020-03-18 20h05 +00:00 Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update allows attackers to unspecified impact via unspecified vectors.
4.8
Medium
CVE-2019-3606 2019-03-26 16h23 +00:00 Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrators to view configuration information in plain text format via the GUI or GUI terminal commands.
7.7
High
CVE-2019-3597 2019-03-26 16h21 +00:00 Authentication Bypass vulnerability in McAfee Network Security Manager (NSM) 9.1 < 9.1.7.75.2 and 9.2 < 9.2.7.31 (9.2 Update 2) allows unauthenticated users to gain administrator rights via incorrect handling of expired GUI sessions.
9.8
Critical
CVE-2018-6681 2018-07-17 11h00 +00:00 Abuse of Functionality vulnerability in the web interface in McAfee Network Security Management (NSM) 9.1.7.11 and earlier allows authenticated users to allow arbitrary HTML code to be reflected in the response web page via appliance web interface.
5.4
Medium