CVE-2017-3936: McAfee ePolicy Orchestrator (ePO) - OS Command Injection vulnerability
OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run arbitrary OS commands with limited privileges via not sanitizing the user input data before exporting it into a CSV format output.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3936?
CVE-2017-3936 is classified as a moderate severity vulnerability due to the potential for unauthorized command execution.
How do I fix CVE-2017-3936?
To mitigate CVE-2017-3936, upgrade to the latest version of McAfee ePolicy Orchestrator that addresses this vulnerability.
What impact does CVE-2017-3936 have on affected systems?
CVE-2017-3936 allows attackers to execute arbitrary operating system commands on affected McAfee ePolicy Orchestrator systems.
Which versions of McAfee ePolicy Orchestrator are affected by CVE-2017-3936?
CVE-2017-3936 affects McAfee ePolicy Orchestrator versions 5.1.0 through 5.9.0.
Is there an exploit available for CVE-2017-3936?
Yes, CVE-2017-3936 can be exploited by crafting malicious input that is not properly sanitized before being processed.