CVE-2015-8989

UnknownEPSS 0.94%

Last modified

CVE-2015-8989 is a vulnerability of currently unknown severity. Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earlier allows attackers to more easily decrypt user passwords via brute force attacks against the database.. EPSS estimates a 0.94% chance of exploitation in the next 30 days.

Description

Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earlier allows attackers to more easily decrypt user passwords via brute force attacks against the database.

Metrics

EPSS Probability
0.94%

56.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
McafeeVulnerability Manager<= 7.5.8

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-8989?
Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earlier allows attackers to more easily decrypt user passwords via brute force attacks against the database.
How severe is CVE-2015-8989?
Severity scoring for CVE-2015-8989 is pending analysis. The EPSS model estimates a 0.94% probability of exploitation in the next 30 days.
How do I fix CVE-2015-8989?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-8989?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST