5.3

CVE-2022-0862

ePO password change vulnerability

A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to change the password of a compromised session without knowing the existing user's password. This functionality was removed from the User Interface in ePO 10 and the API has now been disabled. Other protection is in place to reduce the likelihood of this being successful through sending a link to a logged in user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Epolicy Orchestrator Version < 5.10.0
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update -
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_1
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_10
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_11
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_12
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_2
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_3
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_4
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_5
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_6
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_7
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_8
Mcafee ≫ Epolicy Orchestrator Version 5.10.0 Update update_9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.67% 0.488
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Trellix 3.1 1.6 1.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://kc.mcafee.com/corporate/index?page=content&id=SB10379