Security Advisory

CVE-2017-3965

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-04-04 13:00:00
Last updated 2024-09-16 16:38:11
Assigner trellix
CVSS score 8.8
State PUBLISHED

Description

Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs.