CVE-2020-7308
Summary
| CVE | CVE-2020-7308 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-15 08:15:00 UTC |
| Updated | 2023-11-16 14:22:00 UTC |
| Description | Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI over DNS. By gaining control of an intermediate DNS server or altering the network DNS configuration, it is possible for an attacker to intercept requests and send their own responses. |
Risk And Classification
Problem Types: CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Endpoint Security | 10.6.1 | - | All | All |
| Application | Mcafee | Endpoint Security | 10.6.1 | april_2020 | All | All |
| Application | Mcafee | Endpoint Security | 10.6.1 | december_2018 | All | All |
| Application | Mcafee | Endpoint Security | 10.6.1 | december_2019 | All | All |
| Application | Mcafee | Endpoint Security | 10.6.1 | february_2019 | All | All |
| Application | Mcafee | Endpoint Security | 10.6.1 | february_2020 | All | All |
| Application | Mcafee | Endpoint Security | 10.6.1 | july_2019 | All | All |
| Application | Mcafee | Endpoint Security | 10.6.1 | july_2020 | All | All |
| Application | Mcafee | Endpoint Security | 10.6.1 | may_2019 | All | All |
| Application | Mcafee | Endpoint Security | 10.6.1 | november_2018 | All | All |
| Application | Mcafee | Endpoint Security | 10.6.1 | november_2020 | All | All |
| Application | Mcafee | Endpoint Security | 10.6.1 | october_2019 | All | All |
| Application | Mcafee | Endpoint Security | 10.6.1 | september_2020 | All | All |
| Application | Mcafee | Endpoint Security | 10.7.0 | february_2020 | All | All |
| Application | Mcafee | Endpoint Security | 10.7.0 | july_2020 | All | All |
| Application | Mcafee | Endpoint Security | 10.7.0 | november_2020 | All | All |
| Application | Mcafee | Endpoint Security | 10.7.0 | september_2020 | All | All |
| Application | Mcafee | Endpoint Security | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| McAfee Security Bulletin - Endpoint Security for Windows update fixes one vulnerability (CVE-2020-7308) | kc.mcafee.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.