CVE-2014-2390

Cross-site request forgery (CSRF) vulnerability in the User Management module in McAfee Network Security Manager (NSM) before 6.1.15.39 7.1.5.x before 7.1.5.15, 7.1.15.x before 7.1.15.7, 7.5.x before 7.5.5.9, and 8.x before 8.1.7.3 allows remote attackers to hijack the authentication of users for requests that modify user accounts via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:06

Type Values Removed Values Added
References () http://www.securitytracker.com/id/1030674 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1030674 - Third Party Advisory, VDB Entry
References () https://kc.mcafee.com/corporate/index?page=content&id=SB10081 - Vendor Advisory () https://kc.mcafee.com/corporate/index?page=content&id=SB10081 - Vendor Advisory

Information

Published : 2014-08-29 16:55

Updated : 2024-11-21 02:06


NVD link : CVE-2014-2390

Mitre link : CVE-2014-2390

CVE.ORG link : CVE-2014-2390


JSON object : View

Products Affected

mcafee

  • network_security_manager
CWE
CWE-352

Cross-Site Request Forgery (CSRF)