cve/2020/CVE-2020-7336.md

19 lines
907 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2020-7336](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7336)
![](https://img.shields.io/static/v1?label=Product&message=Network%20Security%20Management%20(NSM)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=NSM%2010.x%3C%2010.1.7.35%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-352%20Cross-Site%20Request%20Forgery%20(CSRF)&color=brighgreen)
### Description
Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.
### POC
#### Reference
- https://kc.mcafee.com/corporate/index?page=content&id=SB10341
2024-06-09 00:33:16 +00:00
- https://kc.mcafee.com/corporate/index?page=content&id=SB10341
2024-05-25 21:48:12 +02:00
#### Github
No PoCs found on GitHub currently.