Vulnerability Description
Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Mvision Endpoint | < 20.11 |
Related Weaknesses (CWE)
References
- https://kc.mcafee.com/corporate/index?page=content&id=SB10334Broken LinkVendor Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10334Broken LinkVendor Advisory
FAQ
What is CVE-2020-7329?
CVE-2020-7329 is a vulnerability with a CVSS score of 7.2 (HIGH). Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully con...
How severe is CVE-2020-7329?
CVE-2020-7329 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7329?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Mvision Endpoint.