CVE-2015-8024
Summary
| CVE | CVE-2015-8024 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-12-02 16:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) 9.3.x before 9.3.2MR19, 9.4.x before 9.4.2MR9, and 9.5.x before 9.5.0MR8, when configured to use Active Directory or LDAP authentication sources, allow remote attackers to bypass authentication by logging in with the username "NGCP|NGCP|NGCP;" and any password. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Mcafee Enterprise Security Manager | 9.3.0 | All | All | All |
| Application | Mcafee | Mcafee Enterprise Security Manager | 9.3.1 | All | All | All |
| Application | Mcafee | Mcafee Enterprise Security Manager | 9.3.2 | All | All | All |
| Application | Mcafee | Mcafee Enterprise Security Manager | 9.4.0 | All | All | All |
| Application | Mcafee | Mcafee Enterprise Security Manager | 9.4.1 | All | All | All |
| Application | Mcafee | Mcafee Enterprise Security Manager | 9.4.2 | All | All | All |
| Application | Mcafee | Mcafee Enterprise Security Manager | 9.5.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| McAfee KnowledgeBase - Intel Security - Security Bulletin: SIEM ESM, ESMREC, and ESMLM updates fix authentication bypass vulnerability | af854a3a-2127-422b-91ae-364da2661108 | kc.mcafee.com | Vendor Advisory |
| McAfee SIEM ESM, ESMREC, and ESMLM Authentication Bypass vulnerability - Quantum leap | af854a3a-2127-422b-91ae-364da2661108 | www.quantumleap.it | |
| McAfee Enterprise Security Manager Lets Remote Users Bypass Authentication on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.