McAfee Vulnerabilities and Affected Products
Vulnerabilities associated with ePolicy Orchestrator (ePO).
Products
Clear product- Network Security Management (NSM)16 vulnerabilities
- Advanced Threat Defense (ATD)12 vulnerabilities
- McAfee Web Gateway (MWG)8 vulnerabilities
- Network Data Loss Prevention (NDLP)8 vulnerabilities
- DLP ePO extension6 vulnerabilities
- ePolicy Orchestrator (ePO)6 vulnerabilities
- McAfee Total Protection (MTP)4 vulnerabilities
- True Key4 vulnerabilities
- McAfee Agent (MA) for Linux3 vulnerabilities
- Network Data Loss Prevention3 vulnerabilities
- Application and Change Control2 vulnerabilities
- Data Loss Prevention (DLP) ePO extension2 vulnerabilities
- Data Loss Prevention Endpoint (DLPe)2 vulnerabilities
- Data Loss Prevention(DLP)2 vulnerabilities
- ePolicy Orchistrator (ePO)2 vulnerabilities
- Live Safe2 vulnerabilities
- True Key (TK)2 vulnerabilities
- antivirus_vpn_for_android1 vulnerability
- Client Proxy (MCP)1 vulnerability
- Common UI (CUI)1 vulnerability
- Data Loss Prevention1 vulnerability
- Data Loss Prevention (DLP) Endpoint1 vulnerability
- Data Loss Prevention (DLP) for Windows1 vulnerability
- Database Security1 vulnerability
- Drive Encryption (MDE)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-6671MEDIUM | SB10240 - ePolicy Orchestrator (ePO) - Application Protection Bypass vulnerabilityApplication Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticated users to bypass localhost only access security protection for some ePO features via a specially crafted HTTP request. Jun 15, 2018 | CVSS4.7v3.0 | EPSS4.7% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-6672MEDIUM | SB10240 - ePolicy Orchestrator (ePO) - Information disclosure vulnerablityInformation disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows authenticated users to view sensitive information in plain text format via unspecified vectors. CWE-200Jun 15, 2018 | CVSS5.7v3.0 | EPSS1.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-3936MEDIUM | McAfee ePolicy Orchestrator (ePO) - OS Command Injection vulnerabilityOS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run arbitrary OS commands with limited privileges via not sanitizing the user input data before exporting it into a CSV format output. CWE-78Jun 13, 2018 | CVSS6.2v3.0 | EPSS1.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
SB10228 ePO Reflected Cross-Site Scripting vulnerabilityReflected Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows remote authenticated users to exploit an XSS issue via not sanitizing the user input. CWE-79Apr 2, 2018 | CVSS3.7v3.0 | EPSS1.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2018-6660MEDIUM | SB10228 ePO Directory Traversal vulnerabilityDirectory Traversal vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows administrators to use Windows alternate data streams, which could be used to bypass the file extensions, via not properly validating the path when exporting a particular XML file. CWE-22Apr 2, 2018 | CVSS6.2v3.0 | EPSS1.69% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-3980HIGH | A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 and earlier allows remote authenticated users to execute a command of their choice via an authenticated ePO session. CWE-22May 18, 2017 | CVSS7.2v3.0 | EPSS2.82% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |