VYPR
High severity7.2NVD Advisory· Published Nov 11, 2020· Updated Jun 17, 2026

CVE-2020-7329

CVE-2020-7329

Description

Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.

Affected products

3
  • cpe:2.3:a:mcafee:mvision_endpoint:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mcafee:mvision_endpoint:*:*:*:*:*:*:*:*range: <20.11
    • (no CPE)range: <20.11
  • McAfee, LLC/MVISION Endpoint ePO extensionv5
    Range: 20.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.