Skip to main content

Vendor/product archive

mcafee / advanced_threat_defense CVEs

Beta · best-effort

26 CVEs tagged to mcafee / advanced_threat_defense3 Critical, 10 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2020-7270

Published Apr 15, 2021

Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted info…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7269

Published Apr 15, 2021

Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted info…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7262

Published Jun 22, 2020

Improper Access Control vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.10.0 allows local users to view sensitive files via a carefully crafted HTTP request param…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7254

Published Mar 12, 2020

Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improp…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3663

Published Nov 14, 2019

Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-3662

Published Nov 14, 2019

Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to gain unintended access to file…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3661

Published Nov 14, 2019

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to e…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3660

Published Nov 13, 2019

Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute commands on the server remotely via c…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3651

Published Nov 13, 2019

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to ePO as an administrator via using…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3650

Published Nov 13, 2019

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to the atduser credentials via carefu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3649

Published Nov 13, 2019

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-4057

Published Jul 12, 2017

Privilege Escalation vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to gain elevated privileges v…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4055

Published Jul 12, 2017

Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attacker…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4054

Published Jul 12, 2017

Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to execute a command of their ch…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4053

Published Jul 12, 2017

Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to execute…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-4052

Published Jul 12, 2017

Authentication Bypass vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to chan…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-3899

Published Mar 14, 2017

SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted H…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8990

Published Mar 14, 2017

Detection bypass vulnerability in Intel Security Advanced Threat Defense (ATD) 3.4.6 and earlier allows malware samples to bypass ATD detection via renaming the malware.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8986

Published Mar 14, 2017

Sandbox detection evasion vulnerability in hardware appliances in McAfee (now Intel Security) Advanced Threat Defense (MATD) 3.4.2.32 and earlier allows attackers to detect the sa…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3983

Published Apr 8, 2016

McAfee Advanced Threat Defense (ATD) before 3.4.8.178 might allow remote attackers to bypass malware detection by leveraging information about the parent process.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3030

Published Apr 8, 2015

The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to obtain sensitive configuration information via unspecified vectors.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3029

Published Apr 8, 2015

The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 does not properly restrict access, which allows remote authenticated users to obtain sensitive informati…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2