PT-2022-13481 · Mcafee · Mcafee Enterprise Epolicy Orchestrator

Published

2022-03-23

·

Updated

2023-07-24

·

CVE-2022-0862

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions McAfee Enterprise ePolicy Orchestrator versions prior to 5.10 Update 13
Description A lack of password change protection in a depreciated API allows a remote attacker to change the password of a compromised session without knowing the existing user's password. This functionality was removed from the User Interface in ePO 10 and the API has now been disabled. Other protection is in place to reduce the likelihood of this being successful through sending a link to a logged in user.
Recommendations For versions prior to 5.10 Update 13, update to version 5.10 Update 13 or later to resolve the issue. As a temporary workaround, consider disabling the depreciated API until a patch is available. Restrict access to the API to minimize the risk of exploitation. Avoid using the API for password changes until the issue is resolved.

Fix

Improper Authentication

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-0862

Affected Products

Mcafee Enterprise Epolicy Orchestrator