CVE-2018-6672: SB10240 - ePolicy Orchestrator (ePO) - Information disclosure vulnerablity
Published Jun 15, 2018
·Updated
Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows authenticated users to view sensitive information in plain text format via unspecified vectors.
Affected Software
2 affected components
McAfee ePolicy Orchestrator>=5.3.0<=5.3.3
McAfee ePolicy Orchestrator>=5.9.0<=5.9.1
Event History
Jun 15, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6672?
CVE-2018-6672 is classified as an information disclosure vulnerability.
2
How do I fix CVE-2018-6672?
To mitigate CVE-2018-6672, it is recommended to upgrade McAfee ePolicy Orchestrator to the latest patched version.
3
What versions of McAfee ePolicy Orchestrator are affected by CVE-2018-6672?
CVE-2018-6672 affects McAfee ePolicy Orchestrator versions 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1.
4
What type of information is disclosed due to CVE-2018-6672?
CVE-2018-6672 allows authenticated users to view sensitive information in plain text format.
5
Can CVE-2018-6672 be exploited by unauthenticated users?
No, CVE-2018-6672 requires authentication to exploit the information disclosure.