PT-2015-4972 · Mcafee · Mcafee Epolicy Orchestrator

Brandon Perry

·

Published

2015-01-09

·

Updated

2017-09-08

·

CVE-2015-0922

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions McAfee ePolicy Orchestrator (ePO) versions prior to 4.6.9 McAfee ePolicy Orchestrator (ePO) versions 5.x prior to 5.1.2
Description The issue allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password, as the same secret key is used across different customers' installations.
Recommendations For versions prior to 4.6.9, update to version 4.6.9 or later. For versions 5.x prior to 5.1.2, update to version 5.1.2 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-0922

Affected Products

Mcafee Epolicy Orchestrator