{"api_version":"1","generated_at":"2026-07-23T12:06:22+00:00","cve":"CVE-2020-7306","urls":{"html":"https://cve.report/CVE-2020-7306","api":"https://cve.report/api/cve/CVE-2020-7306.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-7306","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-7306"},"summary":{"title":"CVE-2020-7306","description":"Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain text","state":"PUBLIC","assigner":"psirt@mcafee.com","published_at":"2020-08-13 03:15:00","updated_at":"2023-11-07 03:25:00"},"problem_types":["CWE-522"],"metrics":[],"references":[{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10326","name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10326","refsource":"","tags":[],"title":"McAfee Security Bulletin - Data Loss Prevention for Mac agent and Data Loss Prevention ePO extension address eight vulnerabilities (CVE-2020-7300, CVE-2020-7301, CVE-2020-7302, CVE-2020-7303, CVE-2020-7304, CVE-2020-7305, CVE-2020-7306, and CVE-2020-7307)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-7306","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7306","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"7306","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"data_loss_prevention","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7306","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"data_loss_prevention","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@mcafee.com","ID":"CVE-2020-7306","STATE":"PUBLIC","TITLE":"DLP  for Mac   - Unprotected Storage of Credentials"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Data Loss Prevention(DLP)","version":{"version_data":[{"version_affected":"<","version_name":"11.3","version_value":"11.3.31"},{"version_affected":"<","version_name":"11.4","version_value":"11.4.200"},{"version_affected":"<","version_name":"11.5","version_value":"11.5.2"}]}}]},"vendor_name":"McAfee"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain text"}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":5.2,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-522: Insufficiently Protected Credentials"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10326","name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10326"}]},"source":{"advisory":"SB10326","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2020-08-13 03:15:00","lastModifiedDate":"2023-11-07 03:25:00","problem_types":["CWE-522"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.2,"baseSeverity":"MEDIUM"},"exploitabilityScore":2,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:data_loss_prevention:*:*:*:*:*:*:*:*","versionStartIncluding":"11.4.0","versionEndExcluding":"11.4.200","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:data_loss_prevention:*:*:*:*:*:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"11.3.31","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:data_loss_prevention:*:*:*:*:*:*:*:*","versionStartIncluding":"11.5.0","versionEndExcluding":"11.5.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"7306","Ordinal":"167585","Title":"CVE-2020-7306","CVE":"CVE-2020-7306","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"7306","Ordinal":"1","NoteData":"Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain text","Type":"Description","Title":null},{"CveYear":"2020","CveId":"7306","Ordinal":"2","NoteData":"2020-08-12","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"7306","Ordinal":"3","NoteData":"2020-08-12","Type":"Other","Title":"Modified"}]}}}