CVE-2022-1257
Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information has been moved to encrypted database files.
Published
2022-04-14T15:15:08.007
Last Modified
2024-11-21T06:40:21.407
Status
Modified
Source
[email protected]
Severity
CVSSv3.1: 6.1 (MEDIUM)
CVSSv2 Vector
AV:L/AC:L/Au:N/C:P/I:N/A:N
- Access Vector: LOCAL
- Access Complexity: LOW
- Authentication: NONE
- Confidentiality Impact: PARTIAL
- Integrity Impact: NONE
- Availability Impact: NONE
Exploitability Score
3.9
Impact Score
2.9
Weaknesses
-
Type: Secondary
CWE-922
-
Type: Primary
CWE-922
Affected Vendors & Products
Type |
Vendor |
Product |
Version/Range |
Vulnerable? |
Application |
mcafee
|
agent
|
< 5.7.6 |
Yes
|
References