Mcafee McAfee Endpoint Security(ENS)是美国迈克菲(Mcafee)公司的一套提供智能协作和先进的威胁防御的框架。该框架支持对实时通信的整个威胁防御生命周期进行控制并进行可操作的威胁取证等。 McAfee Endpoint Security中存在跨站脚本漏洞,该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| McAfee LLC | Endpoint Security (ENS) for Windows | 10.7.x ~ 10.7.0 February 2021 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-23882 | 8.2 HIGH | Improper Access Control in the ENS installer |
| CVE-2021-23878 | 7.3 HIGH | Clear text storage of sensitive Information in ENS |
| CVE-2021-23880 | 6.7 MEDIUM | Improper Access Control in the ENS installer |
| CVE-2021-23883 | 4.0 MEDIUM | Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS) |
No comments yet