First published: Fri Jan 09 2015(Updated: )
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee ePolicy Orchestrator | <=4.6.8 | |
McAfee ePolicy Orchestrator | =5.0.0 | |
McAfee ePolicy Orchestrator | =5.0.1 | |
McAfee ePolicy Orchestrator | =5.1.0 | |
McAfee ePolicy Orchestrator | =5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.