CVE-2015-8024: OS Command Injection
McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) 9.3.x before 9.3.2MR19, 9.4.x before 9.4.2MR9, and 9.5.x before 9.5.0MR8, when configured to use Active Directory or LDAP authentication sources, allow remote attackers to bypass authentication by logging in with the username "NGCP|NGCP|NGCP;" and any password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8024?
CVE-2015-8024 has a medium severity rating due to its impact on authentication mechanisms.
How do I fix CVE-2015-8024?
To fix CVE-2015-8024, upgrade to McAfee Enterprise Security Manager version 9.3.2MR19, 9.4.2MR9, or 9.5.0MR8 or later.
What products are affected by CVE-2015-8024?
CVE-2015-8024 affects McAfee Enterprise Security Manager (ESM), ESM/Log Manager, and ESM/Receiver versions prior to the specified updates.
Can CVE-2015-8024 lead to unauthorized access?
Yes, CVE-2015-8024 can allow remote attackers to bypass authentication when Active Directory or LDAP authentication sources are used.
Is there a workaround for CVE-2015-8024?
A recommended workaround for CVE-2015-8024 is to disable Active Directory or LDAP authentication until the software is updated.