First published: Wed Oct 29 2014(Updated: )
The (1) Removable Media and (2) CD and DVD encryption offsite access options (formerly Endpoint Encryption for Removable Media or EERM) in McAfee File and Removable Media Protection (FRP) 4.3.0.x, and Endpoint Encryption for Files and Folders (EEFF) 3.2.x through 4.2.x, uses a hard-coded salt, which makes it easier for local users to obtain passwords via a brute force attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Endpoint Encryption For Files And Folders | =3.2.0.0 | |
Mcafee Endpoint Encryption For Files And Folders | =3.2.1.0 | |
Mcafee Endpoint Encryption For Files And Folders | =3.2.2.0 | |
Mcafee Endpoint Encryption For Files And Folders | =3.2.4.1 | |
Mcafee Endpoint Encryption For Files And Folders | =3.2.5.0 | |
Mcafee Endpoint Encryption For Files And Folders | =3.2.6 | |
Mcafee Endpoint Encryption For Files And Folders | =3.2.6.3 | |
Mcafee Endpoint Encryption For Files And Folders | =3.2.7 | |
Mcafee Endpoint Encryption For Files And Folders | =3.2.7.0 | |
Mcafee Endpoint Encryption For Files And Folders | =3.2.8 | |
Mcafee Endpoint Encryption For Files And Folders | =3.2.9.0 | |
Mcafee Endpoint Encryption For Files And Folders | =4.0.0 | |
Mcafee Endpoint Encryption For Files And Folders | =4.0.0.0 | |
Mcafee Endpoint Encryption For Files And Folders | =4.0.1 | |
Mcafee Endpoint Encryption For Files And Folders | =4.0.1.0 | |
Mcafee Endpoint Encryption For Files And Folders | =4.1.0 | |
Mcafee Endpoint Encryption For Files And Folders | =4.1.1 | |
Mcafee Endpoint Encryption For Files And Folders | =4.2.0 | |
McAfee File and Removable Media Protection | =4.3.0 | |
McAfee File and Removable Media Protection | =4.3.0.224 | |
McAfee File and Removable Media Protection | =4.3.0.243 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8518 has been classified with a low severity due to the limited impact it poses.
To fix CVE-2014-8518, upgrade to the latest version of McAfee File and Removable Media Protection or Endpoint Encryption for Files and Folders.
CVE-2014-8518 affects McAfee Endpoint Encryption for Files and Folders versions 3.2.x to 4.2.x and McAfee File and Removable Media Protection version 4.3.0.
CVE-2014-8518 is a cryptographic vulnerability due to the use of a hard-coded salt.
CVE-2014-8518 does not provide an exploit vector remotely, as the vulnerability requires local permissions to affect the system.