CVE-2016-8006
Summary
| CVE | CVE-2016-8006 |
|---|---|
| State | PUBLISHED |
| Assigner | intel |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-01-05 22:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Authentication bypass vulnerability in Enterprise Security Manager (ESM) and License Manager (LM) in Intel Security McAfee Security Information and Event Management (SIEM) 9.6.0 MR3 allows an administrator to make changes to other SIEM users' information including user passwords without supplying the current administrator password a second time via the GUI or GUI terminal commands. |
Risk And Classification
Primary CVSS: v3.0 4.4 MEDIUM from [email protected]
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS: 0.000760000 probability, percentile 0.226860000 (date 2026-05-11)
Problem Types: CWE-264 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 4.4 | MEDIUM | CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |
| 2.0 | [email protected] | Primary | 1.7 | AV:L/AC:L/Au:S/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Security Information And Event Management | All | mr3 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| McAfee SIEM 9.6 Authentication bypass vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.narthar.it | |
| McAfee SIEM ESM and ESMREC Authentication Bypass vulnerability - Quantum leap | af854a3a-2127-422b-91ae-364da2661108 | www.quantumleap.it | |
| McAfee Corporate KB - SIEM 9.6.0 MR3 update addresses authentication bypass vulnerability (CVE-2016-8006) KB87744 | af854a3a-2127-422b-91ae-364da2661108 | kc.mcafee.com | Vendor Advisory |
| Multiple McAfee Products CVE-2016-8006 Local Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.