CVE Vulnerabilities

CVE-2017-3912

Improper Handling of Insufficient Privileges

Published: Sep 18, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.

Weakness

The product does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.

Affected Software

Name Vendor Start Version End Version
Application_and_change_control Mcafee 6.2.0 (including) 6.2.0 (including)
Application_and_change_control Mcafee 7.0.1 (including) 7.0.1 (including)

References