CVE-2019-3597: McAfee Network Security Manager

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Authentication Bypass vulnerability in McAfee Network Security Manager (NSM) 9.1 < 9.1.7.75.2 and 9.2 < 9.2.7.31 (9.2 Update 2) allows unauthenticated users to gain administrator rights via incorrect handling of expired GUI sessions.

Affected products

  • McAfee Network Security Manager: from 9.1, before 9.1.7.75 (fixed in 9.1.7.75); from 9.2, before 9.2.7.31 (fixed in 9.2.7.31)

Published 2019-03-26. Last modified 2026-06-17.