CVE-2016-8006 Information
Feb 14, 2021
cve
Description
Authentication bypass vulnerability in Enterprise Security Manager (ESM) and License Manager (LM) in Intel Security McAfee Security Information and Event Management (SIEM) 9.6.0 MR3 allows an administrator to make changes to other SIEM users’ information including user passwords without supplying the current administrator password a second time via the GUI or GUI terminal commands.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Reference
http://www.quantumleap.it/mcafee-siem-esm-esmrec-authentication-bypass-vulnerability/ http://www.securityfocus.com/bid/95313 https://kc.mcafee.com/corporate/index?page=content&id=KB87744 https://www.narthar.it/DOC/McAfee_SIEM_9.6_Authentication_bypass_vulnerability.html
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
4.4
Share on: