CVE-2017-3971 – SB10192 - Network Security Management (NSM) - Cryptanalysis vulnerability
https://notcve.org/view.php?id=CVE-2017-3971
Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential information via insecure use of RC4 encryption cyphers. Vulnerabilidad de criptoanálisis en la interfaz web en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes vean información confidencial mediante el uso inseguro de un cypher de cifrado RC4. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-326: Inadequate Encryption Strength •
CVE-2017-3965 – SB10192 - Network Security Management (NSM) - Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability
https://notcve.org/view.php?id=CVE-2017-3965
Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs. Vulnerabilidad de Cross-Site Request Forgery (CSRF), también conocido como Session Riding, en la interfaz web de Session Riding en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes remotos realicen tareas no autorizadas como la recuperación de información interna del sistema o la manipulación de la base de datos mediante URL especialmente manipuladas. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2017-3967 – SB10192 - Network Security Management (NSM) - Target influence via framing vulnerability
https://notcve.org/view.php?id=CVE-2017-3967
Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to inject arbitrary web script or HTML via application pages inability to break out of 3rd party HTML frames. Vulnerabilidad de influencia de objetivo mediante framing en la interfaz web en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes remotos inyecten scripts web o HTML arbitrarios aprovechándose de la incapacidad de las páginas de aplicación de liberarse de los frames HTML de terceros. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2017-3969 – SB10192 - Network Security Management (NSM) - Abuse of communication channels vulnerability
https://notcve.org/view.php?id=CVE-2017-3969
Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle attackers to decrypt messages via an inadequate implementation of SSL. Vulnerabilidad de abuso de canales de comunicación en el servidor en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes Man-in-the-Middle (MitM) descifren mensajes mediante la implementación inadecuada de SSL. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-417: Communication Channel Errors •
CVE-2017-3972 – SB10192 - Network Security Management (NSM) - Infrastructure-based foot printing vulnerability
https://notcve.org/view.php?id=CVE-2017-3972
Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to execute arbitrary code via the server banner leaking potentially sensitive or security relevant information. Vulnerabilidad de foot printing basada en infraestructura en la interfaz web en McAfee Network Security Management (NSM), en versiones anteriores a la 8.2.7.42.2, permite que atacantes ejecuten código arbitrario mediante el banner del servidor, filtrando información potencialmente sensible o relevante para la seguridad. • https://kc.mcafee.com/corporate/index?page=content&id=SB10192 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •