Enterprise Security Manager

Vendor:

First CVE: Sep 22, 2015 · Active for 10 years

9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Enterprise Security Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 22, 2015
10 years ago
Most Recent CVE
Sep 11, 2019
2,509 days ago

CVE Severity & Scoring

Enterprise Security Manager9 CVEs
All CVEs352,708 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (88.9%)
Unknown1 (11.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High0 (0.0%)
Unknown1 (11.1%)
User Interaction
None7 (77.8%)
Unknown1 (11.1%)
Required1 (11.1%)
Privileges Required
Low2 (22.2%)
High2 (22.2%)
None4 (44.4%)
Unknown1 (11.1%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to gain elevated privileges via speciall
Jun 27, 20198.828NONO
McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially leading to a denial of service. This affects the scanning pr
Sep 11, 20197.525NONO
Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially cr
Jun 27, 20197.225NONO
Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially cr
Jun 27, 20197.225NONO
McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9517, potentially leading to a denial of service. This affects the scanning pr
Sep 11, 20197.524NONO
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.
Aug 7, 20177.523NONO
Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows unauthenticated user to impersonate system users
Jun 27, 20196.522NONO
Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain access to a core system component via incorrect access contr
Jun 27, 20198.822NONO
McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8
Sep 22, 20156.522NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Enterprise Security Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
11.2.027.52.4%00
11.1.327.52.4%00
11.1.227.52.4%00
11.1.127.52.4%00
11.1.027.52.4%00
11.0.027.52.4%00
10.4.027.52.4%00
10.3.427.52.4%00
10.2.027.52.4%00