CVE-2020-7307

Published Aug 13, 2020

Last updated a year ago

Overview

Description
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing plain text credentials.
Source
trellixpsirt@trellix.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
5.2
Impact score
2.7
Exploitability score
2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
2.1
Impact score
2.9
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

nvd@nist.gov
CWE-522
trellixpsirt@trellix.com
CWE-522

Social media

Hype score
Not currently trending

Configurations