CVE-2015-0922: Infoleak
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0922?
CVE-2015-0922 has a medium severity rating, indicating a potential risk to affected systems.
How do I fix CVE-2015-0922?
To fix CVE-2015-0922, update McAfee ePolicy Orchestrator to version 4.6.9 or 5.1.2 or higher.
What versions of ePolicy Orchestrator are affected by CVE-2015-0922?
CVE-2015-0922 affects ePolicy Orchestrator versions prior to 4.6.9 and 5.x versions prior to 5.1.2.
What kind of attack can exploit CVE-2015-0922?
CVE-2015-0922 can be exploited by attackers to obtain the administrator password through knowledge of the encrypted password.
Is there a workaround for CVE-2015-0922?
There are no documented workarounds for CVE-2015-0922; updating to a secure version is necessary.