CVE-2015-2859: Medium severity mcafee epolicy orchestrator vulnerability
Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certification Authority names in X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2859?
CVE-2015-2859 is classified as a high-severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2015-2859?
To fix CVE-2015-2859, update your Intel McAfee ePolicy Orchestrator to version 5.1.3 or later.
What does CVE-2015-2859 affect?
CVE-2015-2859 affects multiple versions of Intel McAfee ePolicy Orchestrator, including versions from 4.x through 5.1.2.
What type of attack does CVE-2015-2859 allow?
CVE-2015-2859 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via crafted certificates.
Is CVE-2015-2859 still a risk in the latest versions of ePolicy Orchestrator?
No, CVE-2015-2859 is mitigated in versions of ePolicy Orchestrator released after 5.1.2.