Skip to main content

Cleartext Storage of Sensitive Information

CVE-2019-3606

Severity High
Score 7.7/10

Summary

Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrators to view configuration information in plain text format via the GUI or GUI terminal commands.

  • LOW
  • LOCAL
  • HIGH
  • CHANGED
  • REQUIRED
  • HIGH
  • HIGH
  • HIGH

CWE-312 - Cleartext Storage of Sensitive Information

The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

References

Advisory Timeline

  • Published