Network Security Manager
Vendor:
First CVE: Aug 29, 2014 · Active for 11 years
19
Total CVEs
More Total CVEs than 93% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Network Security Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 29, 2014
11 years ago
Most Recent CVE
Dec 9, 2021
1,688 days ago
CVE Severity & Scoring
Network Security Manager19 CVEs
68%
11%
21%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.3%)
Network17 (89.5%)
Unknown1 (5.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (84.2%)
High2 (10.5%)
Unknown1 (5.3%)
User Interaction
None9 (47.4%)
Unknown1 (5.3%)
Required9 (47.4%)
Privileges Required
Low6 (31.6%)
High5 (26.3%)
None7 (36.8%)
Unknown1 (5.3%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3597CRITICAL Authentication Bypass vulnerability in McAfee Network Security Manager (NSM) 9.1 < 9.1.7.75.2 and 9.2 < 9.2.7.31 (9.2 Update 2) allows unauthenticated users to gain administrator r | Mar 26, 2019 | 9.8 | 29 | NO | NO |
CVE-2017-3960HIGH Exploitation of Authorization vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to gain elevated privilege | Jun 12, 2018 | 8.8 | 27 | NO | NO |
CVE-2017-3962CRITICAL Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to | Jun 12, 2018 | 9.8 | 26 | NO | NO |
CVE-2017-3972CRITICAL Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to execute arbitrary code via t | Apr 3, 2018 | 9.8 | 26 | NO | NO |
CVE-2017-3968CRITICAL Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allow | Jun 13, 2018 | 9.1 | 24 | NO | NO |
CVE-2017-3965HIGH Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to p | Apr 4, 2018 | 8.8 | 22 | NO | NO |
CVE-2021-4038MEDIUM Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administra | Dec 9, 2021 | 4.8 | 19 | NO | NO |
CVE-2019-3602MEDIUM Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) Prior to 9.1 Update 5 allows an authenticated administrator to embed an XSS in the administrator i | May 15, 2019 | 4.8 | 19 | NO | NO |
CVE-2018-6681MEDIUM Abuse of Functionality vulnerability in the web interface in McAfee Network Security Management (NSM) 9.1.7.11 and earlier allows authenticated users to allow arbitrary HTML code t | Jul 17, 2018 | 5.4 | 19 | NO | NO |
CVE-2017-3971MEDIUM Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential information via insecure use of | Apr 4, 2018 | 6.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Network Security Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1 | 1 | 4.8 | 0.6% | 0 | 0 |