PT-2022-21777 · Mcafee · Mcafee Epo

Published

2022-10-18

·

Updated

2022-10-20

·

CVE-2022-3338

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions McAfee ePO versions prior to 5.10 Update 14
Description The issue allows an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack by exploiting an External XML entity (XXE) vulnerability. This can be done by mimicking the Agent Handler call to ePO and passing a carefully constructed XML file through the API.
Recommendations For versions prior to 5.10 Update 14, update to version 5.10 Update 14 or later to resolve the issue. As a temporary workaround, consider restricting access to the API endpoint to minimize the risk of exploitation.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2022-3338

Affected Products

Mcafee Epo