187
VMScore

CVE-2019-3663

Published: 14/11/2019 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) before 4.8 allows local malicious user to gain access to the root password via accessing sensitive files on the system. This was originally published with a CVSS rating of High, further investigation has resulted in this being updated to Critical. The root password is common across all instances of ATD before 4.8. See the Security bulletin for further details

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mcafee advanced threat defense

Github Repositories

McAfee Advanced Threat Defense ATD 4.6.x and earlier - Hardcoded root password

McAfee ATD CVE-2019-3663 McAfee Advanced Threat Defense ATD 46x and earlier - Hardcoded root password Security Bulletin: kcmcafeecom/corporate/index?page=content&id=SB10304 Interesting shadow entries root:$6$hHb7yjP/$JY9Zf8jFCL966X8rbOqerkuXR86AUMl4bNCuDiEgoXWZEE5dWssWvnokv54YG4/KRQuNbZBiUWur2/Tj4uUf0:18030:0:99999:7::: lb:$6$ewB2mx1KaJArlbX$Bk8y21qhRblg