VendorsMcAfeeadvanced_threat_defenseall versions
Vulnerabilities

McAfee Advanced Threat Defense (MATD)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2017-4053
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to execute a command of their choice via a crafted HTTP request parameter.
Published 2017-07-12 · Modified
9.8EPSS 0.034
CVE-2017-4052
Authentication Bypass vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to change or update any configuration settings, or gain administrator functionality via a crafted HTTP request parameter.
Published 2017-07-12 · Modified
9.8EPSS 0.021
CVE-2019-3663
Advanced Threat Defense (ATD) - Unprotected storage of shared credentials vulnerability
Published 2019-11-13 · Modified
9.8EPSS 0.009
CVE-2017-4054
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to execute a command of their choice via a crafted HTTP request parameter.
Published 2017-07-12 · Modified
8.8EPSS 0.026
CVE-2017-4057
Privilege Escalation vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to gain elevated privileges via the GUI or GUI terminal commands.
Published 2017-07-12 · Modified
8.8EPSS 0.012
CVE-2019-3660
Advanced Threat Defense (ATD) - Improper Neutralization of HTTP requests
Published 2019-11-13 · Modified
8.8EPSS 0.012
CVE-2019-3661
Advanced Threat Defense (ATD) - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Published 2019-11-13 · Modified
8.8EPSS 0.011
CVE-2019-3651
Advanced Threat Defense (ATD) - Information Disclosure vulnerability
Published 2019-11-13 · Modified
8.8EPSS 0.011
CVE-2020-7254
Privilege escalation in Advanced Threat Defense
Published 2020-03-12 · Modified
7.8EPSS 0.003
CVE-2019-3644
MWG scanners updated to address CVE-2019-9517
Published 2019-09-11 · Modified
7.5EPSS 0.024
CVE-2019-3643
MWG scanners updated to address CVE-2019-9511
Published 2019-09-11 · Modified
7.5EPSS 0.024
CVE-2017-4055
Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to bypass ATD detection via loose enforcement of authentication and authorization.
Published 2017-07-12 · Modified
7.5EPSS 0.014
CVE-2015-8990
Detection bypass vulnerability in Intel Security Advanced Threat Defense (ATD) 3.4.6 and earlier allows malware samples to bypass ATD detection via renaming the malware.
Published 2017-03-14 · Modified
7.5EPSS 0.010
CVE-2016-3983
McAfee Advanced Threat Defense (ATD) before 3.4.8.178 might allow remote attackers to bypass malware detection by leveraging information about the parent process.
Published 2016-04-08 · Modified
7.5EPSS 0.006
CVE-2023-0978
A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack
Published 2023-03-13 · Modified
6.7EPSS 0.004
CVE-2017-3899
SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted HTTP request parameter.
Published 2017-03-14 · Modified
6.5EPSS 0.017
CVE-2019-3662
Advanced Threat Defense (ATD) - Path Traversal: '/absolute/pathname/here' vulnerability
Published 2019-11-13 · Modified
6.5EPSS 0.014
CVE-2019-3650
Advanced Threat Defense (ATD) - Information Disclosure vulnerability
Published 2019-11-13 · Modified
6.5EPSS 0.009
CVE-2019-3649
Advanced Threat Defense (ATD) - Information Disclosure vulnerability
Published 2019-11-13 · Modified
6.5EPSS 0.009
CVE-2015-3028
McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to bypass intended restrictions and change or update configuration settings via crafted parameters.
Published 2015-04-08 · Modified
5.5EPSS 0.010
CVE-2020-7262
Improper Access Control vulnerability in ATD
Published 2020-06-22 · Modified
5.5EPSS 0.007
CVE-2015-8986
Sandbox detection evasion vulnerability in hardware appliances in McAfee (now Intel Security) Advanced Threat Defense (MATD) 3.4.2.32 and earlier allows attackers to detect the sandbox environment, then bypass proper malware detection resulting in failure to detect a malware file (false-negative) via specially crafted malware.
Published 2017-03-14 · Modified
5.5EPSS 0.007
CVE-2020-7270
Sensitive Information Exposure in McAfee ATD
Published 2021-04-15 · Modified
4.9EPSS 0.008
CVE-2020-7269
Sensitive Information Exposure in McAfee ATD
Published 2021-04-15 · Modified
4.9EPSS 0.007
CVE-2015-3030
The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to obtain sensitive configuration information via unspecified vectors.
Published 2015-04-08 · Modified
4.0EPSS 0.009
CVE-2015-3029
The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 does not properly restrict access, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
Published 2015-04-08 · Modified
4.0EPSS 0.009