CVE-2015-8989
high
CVSS v3
8.8
CVSS v2
4.0
VIR risk
8.8
Description
Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earlier allows attackers to more easily decrypt user passwords via brute force attacks against the database.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secure@intel.com — https://kc.mcafee.com/corporate/index?page=content&id=SB10117
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| mcafee | vulnerability_manager | {"endIncluding":"7.5.8"} | |
References
CWEs
CWE-310
Verify integrity in audit chain (admin only). AS-IS.