6.5
CVE-2021-23890
- EPSS 0.91%
- Veröffentlicht 26.03.2021 10:15:12
- Zuletzt bearbeitet 21.11.2024 05:52:00
- Erkennungen
McAfee ePO Information Leak vulnerability
Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows an unauthenticated user to download McAfee product packages (specifically McAfee Agent) available in ePO repository and install them on their own machines to have it managed and then in turn get policy details from the ePO server. This can only happen when the ePO Agent Handler is installed in a Demilitarized Zone (DMZ) to service machines not connected to the network through a VPN.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Epolicy Orchestrator Version < 5.9.1
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update -
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_1
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_2
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_3
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_4
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_5
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_6
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_7
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_8
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.91% | 0.551 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
| NIST | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
| Trellix | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://kc.mcafee.com/corporate/index?page=content&id=SB10352