High severity7.2NVD Advisory· Published Nov 11, 2020· Updated Jun 17, 2026
CVE-2020-7329
CVE-2020-7329
Description
Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.
Affected products
3cpe:2.3:a:mcafee:mvision_endpoint:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mcafee:mvision_endpoint:*:*:*:*:*:*:*:*range: <20.11
- (no CPE)range: <20.11
- McAfee, LLC/MVISION Endpoint ePO extensionv5Range: 20.x
Patches
Vulnerability mechanics
References
1- kc.mcafee.com/corporate/indexnvdBroken LinkVendor Advisory
News mentions
0No linked articles in our index yet.