CVE-2017-3968: McAfee Network Data Loss Prevention
Critical severity, CVSS 9.1. EPSS: 1.5% chance of exploitation in the next 30 days.
Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.
Affected products
- McAfee Network Data Loss Prevention: before 9.3.4.1.5 (fixed in 9.3.4.1.5)
- McAfee Network Security Manager: before 8.2.7.42.2 (fixed in 8.2.7.42.2)
Published 2018-06-13. Last modified 2026-06-17.