{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T16:23:48.246","vulnerabilities":[{"cve":{"id":"CVE-2017-3968","sourceIdentifier":"trellixpsirt@trellix.com","published":"2018-06-13T20:29:00.213","lastModified":"2026-06-17T01:19:12.200","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie."},{"lang":"es","value":"Vulnerabilidad de fijación de sesión en la interfaz web en McAfee Network Security Manager (NSM) en versiones anteriores a la 8.2.7.42.2 y McAfee Network Data Loss Prevention (NDLP) en versiones anteriores a la 9.3.4.1.5 permite que atacantes remotos revelen información sensible o manipulen la base de datos mediante una cookie de autenticación manipulada."}],"affected":[{"source":"trellixpsirt@trellix.com","affectedData":[{"vendor":"McAfee","product":"Network Security Management (NSM)","platforms":["x86"],"versions":[{"version":"8","lessThan":"8.2.7.42.2","versionType":"custom","status":"affected"}]},{"vendor":"McAfee","product":"Network Data Loss Prevention (NDLP)","platforms":["x86"],"versions":[{"version":"9.3","lessThan":"9.3.4.1.5 Hotfix 1201697_47868","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"trellixpsirt@trellix.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.7,"impactScore":5.3},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-384"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mcafee:network_data_loss_prevention:*:*:*:*:*:*:*:*","versionEndExcluding":"9.3.4.1.5","matchCriteriaId":"2EBD64DA-659A-4EA6-9DAA-CD2431B21531"},{"vulnerable":true,"criteria":"cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*","versionEndExcluding":"8.2.7.42.2","matchCriteriaId":"1BAB1F42-EE61-4A4E-BFAA-550B220CA0EB"}]}]}],"references":[{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10192","source":"trellixpsirt@trellix.com"},{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10198","source":"trellixpsirt@trellix.com"},{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10192","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10198","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}