CVE-2014-2205: Medium severity McAfee ePolicy Orchestrator vulnerability
The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External Entity (XXE) issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
McAfee ePolicy Orchestrator (ePO) Import and Export Frameworkto a version that resolves this vulnerability.Fixed in 4.6.7 Hotfix 940148Patch 940148
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2205?
CVE-2014-2205 has a high severity rating due to its potential for unauthorized access and exploitation of sensitive files.
How do I fix CVE-2014-2205?
To fix CVE-2014-2205, update McAfee ePolicy Orchestrator to version 4.6.7 Hotfix 940148 or above.
Who is affected by CVE-2014-2205?
CVE-2014-2205 affects users of McAfee ePolicy Orchestrator versions prior to 4.6.7 Hotfix 940148.
What type of vulnerability is CVE-2014-2205?
CVE-2014-2205 is classified as an XML External Entity (XXE) vulnerability.
Can CVE-2014-2205 be exploited remotely?
Yes, CVE-2014-2205 can be exploited by remote authenticated users who have permissions to add dashboards.