Data Loss Prevention
Vendor:
First CVE: Nov 14, 2019 · Active for 6 years
12
Total CVEs
More Total CVEs than 91% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Data Loss Prevention over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 14, 2019
6 years ago
Most Recent CVE
Jan 24, 2022
1,646 days ago
CVE Severity & Scoring
Data Loss Prevention12 CVEs
75%
25%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (25.0%)
Network7 (58.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (16.7%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (75.0%)
Unknown0 (0.0%)
Required3 (25.0%)
Privileges Required
Low10 (83.3%)
High2 (16.7%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4088HIGH SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.101, and 11.6.401 allows a remote authenticated attacker to i | Jan 24, 2022 | 7.2 | 25 | NO | NO |
CVE-2020-7305MEDIUM Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to create new rule sets via incorrect | Aug 13, 2020 | 6.5 | 22 | NO | NO |
CVE-2020-7302MEDIUM Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the D | Aug 13, 2020 | 6.4 | 21 | NO | NO |
CVE-2019-3640MEDIUM Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login detail | Nov 14, 2019 | 6.5 | 21 | NO | NO |
CVE-2020-7346HIGH Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker through the use of junctions to cause | Mar 23, 2021 | 7.8 | 20 | NO | NO |
CVE-2020-7307MEDIUM Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password | Aug 13, 2020 | 5.2 | 19 | NO | NO |
CVE-2020-7304HIGH Cross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to embed a CRSF script via adding a | Aug 13, 2020 | 7.6 | 19 | NO | NO |
CVE-2021-31832MEDIUM Improper Neutralization of Input in the ePO administrator extension for McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a remote ePO DLP administrat | Jun 9, 2021 | 4.8 | 18 | NO | NO |
CVE-2020-7301MEDIUM Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to trigger alerts via the file upload tab in th | Aug 12, 2020 | 4.6 | 18 | NO | NO |
CVE-2020-7300MEDIUM Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to change the configuration when logge | Aug 12, 2020 | 6.3 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Data Loss Prevention
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.6.401 | 1 | 7.2 | 2.3% | 0 | 0 |