CVE-2018-6671: SB10240 - ePolicy Orchestrator (ePO) - Application Protection Bypass vulnerability
Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticated users to bypass localhost only access security protection for some ePO features via a specially crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6671?
CVE-2018-6671 has a medium severity rating, indicating a potential security risk for affected systems.
How do I fix CVE-2018-6671?
To fix CVE-2018-6671, upgrade your McAfee ePolicy Orchestrator to a version that is not vulnerable, such as 5.3.4 or 5.9.2 and above.
Who is affected by CVE-2018-6671?
CVE-2018-6671 affects McAfee ePolicy Orchestrator versions 5.3.0 to 5.3.3 and 5.9.0 to 5.9.1.
What type of vulnerability is CVE-2018-6671?
CVE-2018-6671 is an Application Protection Bypass vulnerability that allows remote authenticated users to circumvent security restraints.
Can CVE-2018-6671 be exploited remotely?
Yes, CVE-2018-6671 can be exploited remotely by authenticated users through specially crafted HTTP requests.