CVE-2019-3604: ePolicy Orchestrator Cloud update fixes multiple Cross-Site Request Forgery vulnerabilities
Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an authenticated user's session via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3604?
CVE-2019-3604 has been classified as a critical severity vulnerability due to its potential for exploitation by unauthenticated users.
How do I fix CVE-2019-3604?
To fix CVE-2019-3604, apply the latest security patches provided by McAfee for ePolicy Orchestrator.
What types of attacks are possible with CVE-2019-3604?
CVE-2019-3604 allows attackers to perform Cross-Site Request Forgery (CSRF) actions, which can manipulate ePO settings using an authenticated user's session.
Who is impacted by CVE-2019-3604?
Organizations using the affected versions of McAfee ePolicy Orchestrator are vulnerable to CVE-2019-3604.
What versions of McAfee ePolicy Orchestrator are affected by CVE-2019-3604?
CVE-2019-3604 affects various legacy versions of McAfee ePolicy Orchestrator before applying the necessary updates.