6.4
CVSSv2

CVE-2020-7308

Published: 15/04/2021 Updated: 16/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows before 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote malicious user to view the requests from ENS and responses from GTI over DNS. By gaining control of an intermediate DNS server or altering the network DNS configuration, it is possible for an malicious user to intercept requests and send their own responses.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mcafee endpoint security 10.7.0

mcafee endpoint security 10.6.1

mcafee endpoint security