CVE-2017-3964 – SB10192 - Network Security Management (NSM) - Reflective Cross-Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2017-3964
Reflective Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to inject arbitrary web script or HTML via a URL parameter. Vulnerabilidad de Cross-Site Scripting (XSS) reflejado en la interfaz web en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes inyecten scripts web o HTML arbitrarios mediante un parámetro URL. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-3966 – SB10192 - Network Security Management (NSM) - Exploitation of session variables, resource IDs and other trusted credentials vulnerability
https://notcve.org/view.php?id=CVE-2017-3966
Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to exploit or harm a user's browser via reusing the exposed session token in the application URL. Vulnerabilidad de explotación de variables de sesión, ID de los recursos y otras credenciales de confianza en la interfaz web en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes remotos exploten o dañen el navegador de un usuario reutilizando el token de sesión expuesto en la URL de la aplicación. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-613: Insufficient Session Expiration •
CVE-2017-3971 – SB10192 - Network Security Management (NSM) - Cryptanalysis vulnerability
https://notcve.org/view.php?id=CVE-2017-3971
Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential information via insecure use of RC4 encryption cyphers. Vulnerabilidad de criptoanálisis en la interfaz web en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes vean información confidencial mediante el uso inseguro de un cypher de cifrado RC4. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-326: Inadequate Encryption Strength •
CVE-2017-3965 – SB10192 - Network Security Management (NSM) - Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability
https://notcve.org/view.php?id=CVE-2017-3965
Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs. Vulnerabilidad de Cross-Site Request Forgery (CSRF), también conocido como Session Riding, en la interfaz web de Session Riding en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes remotos realicen tareas no autorizadas como la recuperación de información interna del sistema o la manipulación de la base de datos mediante URL especialmente manipuladas. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2017-3967 – SB10192 - Network Security Management (NSM) - Target influence via framing vulnerability
https://notcve.org/view.php?id=CVE-2017-3967
Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to inject arbitrary web script or HTML via application pages inability to break out of 3rd party HTML frames. Vulnerabilidad de influencia de objetivo mediante framing en la interfaz web en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes remotos inyecten scripts web o HTML arbitrarios aprovechándose de la incapacidad de las páginas de aplicación de liberarse de los frames HTML de terceros. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-94: Improper Control of Generation of Code ('Code Injection') •