Network Data Loss Prevention

Vendor:

First CVE: Aug 18, 2004 · Active for 21 years

31
Total CVEs
More Total CVEs than 97% of tracked products
7.8
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
5.0
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Network Data Loss Prevention over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 18, 2004
21 years ago
Most Recent CVE
Jun 13, 2018
2,967 days ago

CVE Severity & Scoring

Network Data Loss Prevention31 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (35.5%)
Unknown20 (64.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (32.3%)
High1 (3.2%)
Unknown20 (64.5%)
User Interaction
None7 (22.6%)
Unknown20 (64.5%)
Required4 (12.9%)
Privileges Required
Low3 (9.7%)
High1 (3.2%)
None7 (22.6%)
Unknown20 (64.5%)

Top CVEs

Signals from CVEs in this product scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by
Aug 18, 20045.074NOYES
Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via
May 17, 20176.131NOYES
Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, and remove users via modificati
May 17, 20178.025NONO
Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allow
Jun 13, 20189.124NONO
Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the response body, potentially causing
Oct 31, 20177.521NONO
Privilege Escalation vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via modifica
May 17, 20176.521NONO
The MySQL database in McAfee Network Data Loss Prevention (NDLP) before 9.3 does not require a password, which makes it easier for remote attackers to obtain access.
Oct 29, 20147.521NONO
Web Server method disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to exploit and find another hole via HTTP response header.
May 17, 20175.320NONO
Banner Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to obtain product information via HTTP response header.
May 17, 20175.320NONO
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to execute arbitrary code via vectors related to ICMP redirection.
Oct 29, 20147.520NONO

Exploit Exposure

Signals from CVEs in this product scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.2% of CVEs· 97th percentile
ExploitDB
1 CVE
3.2% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (31 CVEs).

Media Mentions

Signals from CVEs in this product scope (31 CVEs).

Top CNAs Publishing CVEs For Network Data Loss Prevention

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.3.415.40.6%00
9.3.315.40.6%00
9.3.215.40.6%00
9.3.115.40.6%00
9.3.015.40.6%00
9.2.215.080.3%01
9.2.1154.86.2%01
9.2.0204.34.8%01
8.6194.30.8%00