CVE Vulnerabilities

CVE-2020-7306

Insufficiently Protected Credentials

Published: Aug 13, 2020 | Modified: Nov 07, 2023
CVSS 3.x
5.2
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain text

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Data_loss_prevention Mcafee 11.3.0 (including) 11.3.31 (excluding)
Data_loss_prevention Mcafee 11.4.0 (including) 11.4.200 (excluding)
Data_loss_prevention Mcafee 11.5.0 (including) 11.5.2 (excluding)

Potential Mitigations

References