McAfee Application Control and Change Control (MACC) - password management security feature bypass (SFB) leading to an authentication bypass
Vulnerability Description
Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-3912
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- McAfee credits Saurabh Tripathi and Sukesh Shetty for reporting this flaw.
References
More from McAfee
View All →Affected Vendor
McAfee
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.