4.3

CVE-2013-0141

Directory traversal vulnerability in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to upload arbitrary files via a crafted request over the Agent-Server communication channel, as demonstrated by writing to the Software/ directory.

Data is provided by the National Vulnerability Database (NVD)
McafeeEpolicy Orchestrator Version <= 4.5.6
McafeeEpolicy Orchestrator Version2.0
McafeeEpolicy Orchestrator Version2.5
McafeeEpolicy Orchestrator Version2.5 Updatesp1
McafeeEpolicy Orchestrator Version2.5.1
McafeeEpolicy Orchestrator Version3.0
McafeeEpolicy Orchestrator Version3.0 Updatesp2a
McafeeEpolicy Orchestrator Version3.5.0
McafeeEpolicy Orchestrator Version3.6.0
McafeeEpolicy Orchestrator Version3.6.1
McafeeEpolicy Orchestrator Version4.0
McafeeEpolicy Orchestrator Version4.5.0
McafeeEpolicy Orchestrator Version4.5.3
McafeeEpolicy Orchestrator Version4.5.4
McafeeEpolicy Orchestrator Version4.5.5
McafeeEpolicy Orchestrator Version4.6.0
McafeeEpolicy Orchestrator Version4.6.1
McafeeEpolicy Orchestrator Version4.6.2
McafeeEpolicy Orchestrator Version4.6.3
McafeeEpolicy Orchestrator Version4.6.4
McafeeEpolicy Orchestrator Version4.6.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.42% 0.611
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 5.5 4.9
AV:A/AC:M/Au:N/C:P/I:P/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.