104485vdb entry
http://www.securityfocus.com/bid/104485 CVE-2018-6671
MEDIUM
SB10240 - ePolicy Orchestrator (ePO) - Application Protection Bypass vulnerability
Record summary
CVE-2018-6671 has a selected CVSS score of 4.7 (medium); EIP currently links 1 catalogued exploit.
Description
Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticated users to bypass localhost only access security protection for some ePO features via a specially crafted HTTP request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ePolicy Orchestrator (ePO)Browse McAfee / ePolicy Orchestrator (ePO) | CVE List | 5.3.0 through 5.3.3 to < 5.3.3 with hotfix EPO5xHF1229850 | affected |
| 5.9.0 through 5.9.1 to < 5.9.1 with hotfix EPO5xHF1229850 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMcAfee ePO 5.9.1 - Registered Executable Local Access BypassExploitDB exploitby leonjzaNot analyzed1 file
References
51041155vdb entry
http://www.securitytracker.com/id/1041155 kc.mcafee.comConfirmation
https://kc.mcafee.com/corporate/index?page=content&id=SB10240 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-6671 46518exploit
https://www.exploit-db.com/exploits/46518