CVE-2017-3980: Path Traversal
A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 and earlier allows remote authenticated users to execute a command of their choice via an authenticated ePO session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3980?
CVE-2017-3980 is classified as a critical vulnerability due to its potential for remote command execution.
How do I fix CVE-2017-3980?
To remediate CVE-2017-3980, update your McAfee ePolicy Orchestrator to a version later than 5.9.1, 5.3.3, or 5.1.3.
Who is affected by CVE-2017-3980?
CVE-2017-3980 affects remote authenticated users of McAfee ePolicy Orchestrator versions 5.9.0, 5.3.2, and 5.1.3.
What type of vulnerability is CVE-2017-3980?
CVE-2017-3980 is a directory traversal vulnerability that allows unauthorized command execution.
Is there a workaround for CVE-2017-3980?
There are no known workarounds for CVE-2017-3980 other than upgrading to a patched version of the software.