Vulnerability Description
A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registry value associated with the McAfee update via the HTTP backend-response.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Livesafe | <= 16.0.2 |
Related Weaknesses (CWE)
References
- http://service.mcafee.com/FAQDocument.aspx?lc=1033&id=TS102723Vendor Advisory
- http://service.mcafee.com/FAQDocument.aspx?lc=1033&id=TS102723Vendor Advisory
FAQ
What is CVE-2017-3898?
CVE-2017-3898 is a vulnerability with a CVSS score of 5.9 (MEDIUM). A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registry...
How severe is CVE-2017-3898?
CVE-2017-3898 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-3898?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Livesafe.