Vulnerability CVE-2012-4589


Published: 2012-08-22

Description:
Login.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

Type:

CWE-DesignError

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Mcafee -> Enterprise mobility manager 

 References:
https://kc.mcafee.com/corporate/index?page=content&id=SB10022

Copyright 2022, cxsecurity.com

 

Back to Top