8

CVE-2023-5444

A Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2 allows a remote low privilege user to successfully add a new user with administrator privileges to the ePO server. This impacts the dashboard area of the user interface. To exploit this the attacker must change the HTTP payload post submission, prior to it reaching the ePO server.

Data is provided by the National Vulnerability Database (NVD)
McafeeEpolicy Orchestrator Version < 5.10.0
McafeeEpolicy Orchestrator Version5.10.0 Updateservice_pack_1_update
McafeeEpolicy Orchestrator Version5.10.0 Updateservice_pack_1_update_1
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_1
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_10
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_11
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_11_hotfix_1
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_11_hotfix_2
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_12
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_13
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_14
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_15
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_2
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_3
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_4
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_5
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_6
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_7
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_8
McafeeEpolicy Orchestrator Version5.10.0 Updateupdate_9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.34% 0.556
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8 2.1 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
trellixpsirt@trellix.com 8 2.1 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.