« Volver al listado

CVE-2017-3896

Estado: ModificadaMedia (5.9)—

Unvalidated parameter vulnerability in the remote log viewing capability in Intel Security McAfee Agent 5.0.x versions prior to 5.0.4.449 allows remote attackers to pass unexpected input parameters via a URL that was not completely validated.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-3896",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "secure@intel.com",
      "affectedData": [
        {
          "vendor": "Intel",
          "product": "McAfee Agent",
          "versions": [
            {
              "status": "affected",
              "version": "5.0.x versions prior to 5.0.4.449"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-02-13T16:59:00.157",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/95903",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1037629",
      "source": "secure@intel.com"
    },
    {
      "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10183",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/95903",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1037629",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10183",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unvalidated parameter vulnerability in the remote log viewing capability in Intel Security McAfee Agent 5.0.x versions prior to 5.0.4.449 allows remote attackers to pass unexpected input parameters via a URL that was not completely validated."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de parámetro no válido en la capacidad de visualización de inicio de sesión remoto en Intel Security McAfee Agent 5.0.x versiones anteriores a 5.0.4.449 permite a atacantes remotos pasar parámetros de entrada inesperados a través de una URL que no fue completamente validada."
    }
  ],
  "lastModified": "2026-06-17T01:19:08.880",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mcafee:mcafee_agent:5.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FCB38941-504D-4F59-BA02-159FE34E3290"
            },
            {
              "criteria": "cpe:2.3:a:mcafee:mcafee_agent:5.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7543F520-79D3-4AF0-A8EE-C57A38C35B20"
            },
            {
              "criteria": "cpe:2.3:a:mcafee:mcafee_agent:5.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B1F4098-35D5-43B6-BF6B-F38091FA7DB8"
            },
            {
              "criteria": "cpe:2.3:a:mcafee:mcafee_agent:5.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB19F73E-DE92-4249-82C6-830D55FC25AE"
            },
            {
              "criteria": "cpe:2.3:a:mcafee:mcafee_agent:5.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2DE7CA65-6B1F-44BF-AC15-F6595313AF91"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@intel.com"
}