CVE Vulnerabilities

CVE-2020-7306

Insufficiently Protected Credentials

Published: Aug 13, 2020 | Modified: Nov 21, 2024
CVSS 3.x
5.2
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain text

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
Data_loss_preventionMcafee11.3.0 (including)11.3.31 (excluding)
Data_loss_preventionMcafee11.4.0 (including)11.4.200 (excluding)
Data_loss_preventionMcafee11.5.0 (including)11.5.2 (excluding)

Potential Mitigations

References