CVE-2004-0038: High severity McAfee ePolicy Orchestrator vulnerability
Published Apr 30, 2004
·Updated
McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.
Affected Software
5 affected components
McAfee ePolicy Orchestrator=2.5
McAfee ePolicy Orchestrator=2.5-sp1
McAfee ePolicy Orchestrator=2.5.1
McAfee ePolicy Orchestrator=3.0
McAfee ePolicy Orchestrator=3.0-sp2a
Remediation
Patch Available
Patch Available
Patch Available
Event History
Apr 30, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0038?
CVE-2004-0038 is considered a critical vulnerability due to the potential for remote command execution.
2
How do I fix CVE-2004-0038?
To mitigate CVE-2004-0038, apply the latest patches and updates provided by McAfee for ePolicy Orchestrator.
3
Which versions of ePolicy Orchestrator are affected by CVE-2004-0038?
CVE-2004-0038 affects McAfee ePolicy Orchestrator versions 2.5.1, 3.0, 3.0 SP2a, 2.5, and 2.5 SP1.
4
What types of attacks are possible due to CVE-2004-0038?
CVE-2004-0038 allows remote attackers to execute arbitrary commands on the affected system.
5
Is authentication required to exploit CVE-2004-0038?
No, CVE-2004-0038 can be exploited without authentication, making it particularly dangerous.