CVE-2014-2390

Cross-site request forgery (CSRF) vulnerability in the User Management module in McAfee Network Security Manager (NSM) before 6.1.15.39 7.1.5.x before 7.1.5.15, 7.1.15.x before 7.1.15.7, 7.5.x before 7.5.5.9, and 8.x before 8.1.7.3 allows remote attackers to hijack the authentication of users for requests that modify user accounts via unspecified vectors.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:network_security_manager:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-08-29 16:55

Updated : 2023-12-10 11:31


NVD link : CVE-2014-2390

Mitre link : CVE-2014-2390

CVE.ORG link : CVE-2014-2390


JSON object : View

Products Affected

mcafee

  • network_security_manager
CWE
CWE-352

Cross-Site Request Forgery (CSRF)