CVE-2016-8016
low
CVSS v3
3.4
CVSS v2
3.5
VIR risk
3.4
Description
Information exposure in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to obtain the existence of unauthorized files on the system via a URL parameter.
Predictions
Exploit likelihood
45%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secure@intel.com — https://kc.mcafee.com/corporate/index?page=content&id=SB10181
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| mcafee | virusscan_enterprise | {"endIncluding":"2.0.3"} | |
References
- http://www.securityfocus.com/bid/94823
- http://www.securitytracker.com/id/1037433
- https://kc.mcafee.com/corporate/index?page=content&id=SB10181
- https://www.exploit-db.com/exploits/40911/
- http://www.securityfocus.com/bid/94823
- http://www.securitytracker.com/id/1037433
- https://kc.mcafee.com/corporate/index?page=content&id=SB10181
- https://www.exploit-db.com/exploits/40911/
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.