CVE-2015-0922

McAfee ePolicy Orchestrator < 4.6.9 and 5.x < 5.1.2 - Authenticated Credential Exposure via Shared Secret Key

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-0922. Includes Metasploit module auxiliary/gather/mcafee_epo_xxe.

AI-analyzed exploit summary This Metasploit module exploits an authenticated XXE vulnerability in McAfee ePolicy Orchestrator to read the keystore.properties file, which contains an encrypted password decryptable with a static key. The exploit requires valid credentials and leverages weak encryption (AES-128-ECB) to recover the database 'sa' user password.

Description

McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.

Exploits (1)

metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/mcafee_epo_xxe.rb

This Metasploit module exploits an authenticated XXE vulnerability in McAfee ePolicy Orchestrator to read the keystore.properties file, which contains an encrypted password decryptable with a static key. The exploit requires valid credentials and leverages weak encryption (AES-128-ECB) to recover the database 'sa' user password.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: McAfee ePolicy Orchestrator
Auth required
Prerequisites: Valid McAfee ePO credentials · Network access to the ePO server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72298
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jan/37
Patch, Vendor Advisory x_refsource_confirm
https://kc.mcafee.com/corporate/index?page=content&id=SB10095
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jan/8
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031519
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99949

Scores

EPSS 0.1335
EPSS Percentile 95.9%

Details

CWE
CWE-200
Status published
Products (5)
mcafee/epolicy_orchestrator 5.0.0
mcafee/epolicy_orchestrator 5.0.1
mcafee/epolicy_orchestrator 5.1.0
mcafee/epolicy_orchestrator 5.1.1
mcafee/epolicy_orchestrator < 4.6.8
Published Jan 09, 2015
Tracked Since Feb 18, 2026