vendor:
ePolicy Orchestrator
by:
@leonjza
6.5
CVSS
MEDIUM
Local Access Bypass
287
CWE
Product Name: ePolicy Orchestrator
Affected Version From: ePO v5.9.1
Affected Version To: ePO v5.9.1
Patch Exists: YES
Related CWE: CVE-2018-6671
CPE: a:mcafee:epolicy_orchestrator
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows Server 2012
2019
McAfee ePO 5.9.1 Registered Executable Local Access Bypass
Specifying an X-Forwarded-For header bypasses the local only check, allowing an attacker to execute arbitrary code on the vulnerable system.
Mitigation:
Install the hotfix EPO5xHF1229850