Files
CVEs-PoC/2017/CVE-2017-3968.md
T
2025-09-29 21:09:30 +02:00

21 lines
1.1 KiB
Markdown

### [CVE-2017-3968](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3968)
![](https://img.shields.io/static/v1?label=Product&message=Network%20Data%20Loss%20Prevention%20(NDLP)&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Network%20Security%20Management%20(NSM)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=9.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Session%20fixation%20vulnerability%0A&color=brightgreen)
### Description
Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.
### POC
#### Reference
- https://kc.mcafee.com/corporate/index?page=content&id=SB10192
- https://kc.mcafee.com/corporate/index?page=content&id=SB10198
#### Github
No PoCs found on GitHub currently.