Vulnerability Description
McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote authenticated users to execute arbitrary OS commands via a crafted filename, which is not properly handled when downloading the file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Enterprise Security Manager | <= 9.3.2 |
| Mcafee | Enterprise Security Manager\/Log Manager | <= 9.3.2 |
| Mcafee | Enterprise Security Manager\/Receiver | <= 9.3.2 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1033654
- https://kc.mcafee.com/corporate/index?page=content&id=SB10133Vendor Advisory
- http://www.securitytracker.com/id/1033654
- https://kc.mcafee.com/corporate/index?page=content&id=SB10133Vendor Advisory
FAQ
What is CVE-2015-7310?
CVE-2015-7310 is a vulnerability with a CVSS score of 6.5 (MEDIUM). McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9...
How severe is CVE-2015-7310?
CVE-2015-7310 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7310?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Enterprise Security Manager, Mcafee Enterprise Security Manager\/Log Manager, Mcafee Enterprise Security Manager\/Receiver.