Vulnerability Description
Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute commands on the server remotely via carefully constructed HTTP requests.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Advanced Threat Defense | < 4.8 |
References
- https://kc.mcafee.com/corporate/index?page=content&id=SB10304
- https://kc.mcafee.com/corporate/index?page=content&id=SB10304
FAQ
What is CVE-2019-3660?
CVE-2019-3660 is a vulnerability with a CVSS score of 8.4 (HIGH). Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute commands on the server remotely via carefully constructed ...
How severe is CVE-2019-3660?
CVE-2019-3660 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-3660?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Advanced Threat Defense.