First published: Tue Jul 18 2006(Updated: )
Directory traversal vulnerability in Framework Service component in McAfee ePolicy Orchestrator agent 3.5.0.x and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the directory and filename in a PropsResponse (PackageType) request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trellix ePolicy Orchestrator | <=3.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3623 is classified as a high severity vulnerability due to its potential for unauthorized file creation.
To fix CVE-2006-3623, you should upgrade to a version of McAfee ePolicy Orchestrator agent later than 3.5.0.
The impact of CVE-2006-3623 includes the ability for remote attackers to create arbitrary files on the affected system.
CVE-2006-3623 affects McAfee ePolicy Orchestrator agent versions 3.5.0 and earlier.
As of now, there are no specific workarounds publicly documented for CVE-2006-3623, so updating is recommended.