CVE-2020-7336 MEDIUM

CVE-2020-7336: Network Security Management (NSM) - Cross Site Request Forgery vulnerability

Vendor Mcafee
Product Network Security Management (NSM)
Weakness CWE-352 · CSRF
Published January 5, 2021
Last update August 4, 2024

CVSS base score

6.6/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

What the vulnerability does

01Description

Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.

Key dates

02Disclosure timeline

January 5, 2021 CVE published
August 4, 2024 Record updated