Vulnerability Details CVE-2019-3630
Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to execute arbitrary code via specially crafted parameters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.0%
CVSS Severity
CVSS v3 Score 8.0
CVSS v2 Score 6.5
Products affected by CVE-2019-3630
-
cpe:2.3:a:mcafee:enterprise_security_manager:10.0.0
-
cpe:2.3:a:mcafee:enterprise_security_manager:10.2.0
-
cpe:2.3:a:mcafee:enterprise_security_manager:10.3.4
-
cpe:2.3:a:mcafee:enterprise_security_manager:11.0.0
-
cpe:2.3:a:mcafee:enterprise_security_manager:11.1.0
-
cpe:2.3:a:mcafee:enterprise_security_manager:11.1.1
-
cpe:2.3:a:mcafee:enterprise_security_manager:11.1.2
-
cpe:2.3:a:mcafee:enterprise_security_manager:11.1.3