Record summary

CVE-2018-6671 has a selected CVSS score of 4.7 (medium); EIP currently links 1 catalogued exploit.

Description

Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticated users to bypass localhost only access security protection for some ePO features via a specially crafted HTTP request.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List5.3.0 through 5.3.3 to < 5.3.3 with hotfix EPO5xHF1229850affected
5.9.0 through 5.9.1 to < 5.9.1 with hotfix EPO5xHF1229850affected

Proofs of concept

1

Catalogued exploits

ExploitDBMcAfee ePO 5.9.1 - Registered Executable Local Access BypassExploitDB exploitby leonjzaNot analyzed1 file
ExploitDB

PoC details

References

5