First published: Fri Aug 01 2003(Updated: )
Directory traversal vulnerability in ePO agent for McAfee ePolicy Orchestrator 3.0 allows remote attackers to read arbitrary files via a certain HTTP request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trellix ePolicy Orchestrator | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0610 has a moderate severity rating due to its potential to allow unauthorized access to sensitive files.
The fix for CVE-2003-0610 involves updating the ePolicy Orchestrator to a version that is not vulnerable to this directory traversal issue.
CVE-2003-0610 specifically affects McAfee ePolicy Orchestrator version 3.0.
Attackers can exploit CVE-2003-0610 by crafting a specific HTTP request that manipulates the file paths to read unauthorized files on the server.
Until a patch is applied, restricting access to the ePolicy Orchestrator can serve as a temporary workaround to mitigate risks associated with CVE-2003-0610.