MEDIUM · 6.5

CVE-2015-7310

McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9...

Vulnerability Description

McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote authenticated users to execute arbitrary OS commands via a crafted filename, which is not properly handled when downloading the file.

CVSS Score

6.5

MEDIUM

AV:N/AC:L/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
McafeeEnterprise Security Manager<= 9.3.2
McafeeEnterprise Security Manager\/Log Manager<= 9.3.2
McafeeEnterprise Security Manager\/Receiver<= 9.3.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-7310?

CVE-2015-7310 is a vulnerability with a CVSS score of 6.5 (MEDIUM). McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9...

How severe is CVE-2015-7310?

CVE-2015-7310 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-7310?

Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Enterprise Security Manager, Mcafee Enterprise Security Manager\/Log Manager, Mcafee Enterprise Security Manager\/Receiver.