CVE-2017-3965: McAfee Network Security Manager
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs.
Affected products
- McAfee Network Security Manager: before 8.2.7.42.2 (fixed in 8.2.7.42.2)
Published 2018-04-04. Last modified 2026-06-17.