Vulnerabilities > Mcafee > Advanced Threat Defense > 3.4

DATE CVE VULNERABILITY TITLE RISK
2017-07-12 CVE-2017-4057 Unspecified vulnerability in Mcafee Advanced Threat Defense
Privilege Escalation vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to gain elevated privileges via the GUI or GUI terminal commands.
network
low complexity
mcafee
8.8
2017-07-12 CVE-2017-4055 Missing Authentication for Critical Function vulnerability in Mcafee Advanced Threat Defense
Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to bypass ATD detection via loose enforcement of authentication and authorization.
network
low complexity
mcafee CWE-306
7.5
2017-07-12 CVE-2017-4054 Command Injection vulnerability in Mcafee Advanced Threat Defense
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to execute a command of their choice via a crafted HTTP request parameter.
network
low complexity
mcafee CWE-77
8.8
2017-07-12 CVE-2017-4053 OS Command Injection vulnerability in Mcafee Advanced Threat Defense
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to execute a command of their choice via a crafted HTTP request parameter.
network
low complexity
mcafee CWE-78
critical
9.8
2017-07-12 CVE-2017-4052 Missing Authentication for Critical Function vulnerability in Mcafee Advanced Threat Defense
Authentication Bypass vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to change or update any configuration settings, or gain administrator functionality via a crafted HTTP request parameter.
network
low complexity
mcafee CWE-306
critical
9.8
2017-03-14 CVE-2017-3899 SQL Injection vulnerability in Mcafee Advanced Threat Defense
SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted HTTP request parameter.
network
low complexity
mcafee CWE-89
6.5
2017-03-14 CVE-2015-8990 7PK - Security Features vulnerability in Mcafee Advanced Threat Defense
Detection bypass vulnerability in Intel Security Advanced Threat Defense (ATD) 3.4.6 and earlier allows malware samples to bypass ATD detection via renaming the malware.
network
low complexity
mcafee CWE-254
7.5
2017-03-14 CVE-2015-8986 7PK - Security Features vulnerability in Mcafee Advanced Threat Defense 3.4/3.4.2.32
Sandbox detection evasion vulnerability in hardware appliances in McAfee (now Intel Security) Advanced Threat Defense (MATD) 3.4.2.32 and earlier allows attackers to detect the sandbox environment, then bypass proper malware detection resulting in failure to detect a malware file (false-negative) via specially crafted malware.
local
low complexity
mcafee CWE-254
5.5
2016-04-08 CVE-2016-3983 Insufficient Verification of Data Authenticity vulnerability in Mcafee Advanced Threat Defense
McAfee Advanced Threat Defense (ATD) before 3.4.8.178 might allow remote attackers to bypass malware detection by leveraging information about the parent process.
network
low complexity
mcafee CWE-345
7.5