PT-2022-13481 · Mcafee · Mcafee Enterprise Epolicy Orchestrator
Published
2022-03-23
·
Updated
2023-07-24
·
CVE-2022-0862
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
McAfee Enterprise ePolicy Orchestrator versions prior to 5.10 Update 13
Description
A lack of password change protection in a depreciated API allows a remote attacker to change the password of a compromised session without knowing the existing user's password. This functionality was removed from the User Interface in ePO 10 and the API has now been disabled. Other protection is in place to reduce the likelihood of this being successful through sending a link to a logged in user.
Recommendations
For versions prior to 5.10 Update 13, update to version 5.10 Update 13 or later to resolve the issue. As a temporary workaround, consider disabling the depreciated API until a patch is available. Restrict access to the API to minimize the risk of exploitation. Avoid using the API for password changes until the issue is resolved.
Fix
Improper Authentication
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcafee Enterprise Epolicy Orchestrator