CVE-2016-8024 describes an improper neutralization of CRLF sequences in HTTP headers within Intel Security VirusScan Enterprise Linux (VSEL) versions 2.0.3 and earlier. This vulnerability allows a remote, unauthenticated attacker to obtain sensitive information through server HTTP response spoofing. With a CVSS score of 8.1 (HIGH), the attack vector is network-based with high attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild, an exploit for remote code execution (EDB-40911) exists for earlier versions of the affected product, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.3CPE matchmatch criteria | cpe:2.3:a:mcafee:virusscan_enterprise:*:*:*:*:*:linux:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.