Enterprise Security Manager
Vendor:
First CVE: Sep 22, 2015 · Active for 10 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Enterprise Security Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 22, 2015
10 years ago
Most Recent CVE
Sep 11, 2019
2,509 days ago
CVE Severity & Scoring
Enterprise Security Manager9 CVEs
22%
78%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (88.9%)
Unknown1 (11.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High0 (0.0%)
Unknown1 (11.1%)
User Interaction
None7 (77.8%)
Unknown1 (11.1%)
Required1 (11.1%)
Privileges Required
Low2 (22.2%)
High2 (22.2%)
None4 (44.4%)
Unknown1 (11.1%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3632HIGH Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to gain elevated privileges via speciall | Jun 27, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-3643HIGH McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially leading to a denial of service. This affects the scanning pr | Sep 11, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-3631HIGH Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially cr | Jun 27, 2019 | 7.2 | 25 | NO | NO |
CVE-2019-3630HIGH Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially cr | Jun 27, 2019 | 7.2 | 25 | NO | NO |
CVE-2019-3644HIGH McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9517, potentially leading to a denial of service. This affects the scanning pr | Sep 11, 2019 | 7.5 | 24 | NO | NO |
CVE-2015-7704HIGH The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages. | Aug 7, 2017 | 7.5 | 23 | NO | NO |
CVE-2019-3629MEDIUM Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows unauthenticated user to impersonate system users | Jun 27, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-3628HIGH Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain access to a core system component via incorrect access contr | Jun 27, 2019 | 8.8 | 22 | NO | NO |
CVE-2015-7310MEDIUM McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8 | Sep 22, 2015 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Enterprise Security Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.2.0 | 2 | 7.5 | 2.4% | 0 | 0 |
| 11.1.3 | 2 | 7.5 | 2.4% | 0 | 0 |
| 11.1.2 | 2 | 7.5 | 2.4% | 0 | 0 |
| 11.1.1 | 2 | 7.5 | 2.4% | 0 | 0 |
| 11.1.0 | 2 | 7.5 | 2.4% | 0 | 0 |
| 11.0.0 | 2 | 7.5 | 2.4% | 0 | 0 |
| 10.4.0 | 2 | 7.5 | 2.4% | 0 | 0 |
| 10.3.4 | 2 | 7.5 | 2.4% | 0 | 0 |
| 10.2.0 | 2 | 7.5 | 2.4% | 0 | 0 |