Vulnerabilities > Mcafee > Network Security Manager > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-03-26 CVE-2019-3597 Unspecified vulnerability in Mcafee Network Security Manager
Authentication Bypass vulnerability in McAfee Network Security Manager (NSM) 9.1 < 9.1.7.75.2 and 9.2 < 9.2.7.31 (9.2 Update 2) allows unauthenticated users to gain administrator rights via incorrect handling of expired GUI sessions.
network
low complexity
mcafee
critical
9.8
2018-06-13 CVE-2017-3968 Session Fixation vulnerability in Mcafee products
Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.
network
low complexity
mcafee CWE-384
critical
9.1
2018-06-12 CVE-2017-3962 Use of Password Hash With Insufficient Computational Effort vulnerability in Mcafee Network Security Manager
Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to crack user passwords via unsalted hashes.
network
low complexity
mcafee CWE-916
critical
9.8
2018-04-03 CVE-2017-3972 Information Exposure vulnerability in Mcafee Network Security Manager
Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to execute arbitrary code via the server banner leaking potentially sensitive or security relevant information.
network
low complexity
mcafee CWE-200
critical
9.8