CVE-2022-3338: XXE in Trellix ePO server
Published Oct 18, 2022
·Updated
An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and passing the carefully constructed XML file through the API.
Affected Software
15 affected components
McAfee ePolicy Orchestrator<5.10.0
McAfee ePolicy Orchestrator=5.10.0
McAfee ePolicy Orchestrator=5.10.0-update_1
McAfee ePolicy Orchestrator=5.10.0-update_10
McAfee ePolicy Orchestrator=5.10.0-update_11
McAfee ePolicy Orchestrator=5.10.0-update_12
McAfee ePolicy Orchestrator=5.10.0-update_13
McAfee ePolicy Orchestrator=5.10.0-update_2
McAfee ePolicy Orchestrator=5.10.0-update_3
McAfee ePolicy Orchestrator=5.10.0-update_4
McAfee ePolicy Orchestrator=5.10.0-update_5
McAfee ePolicy Orchestrator=5.10.0-update_6
McAfee ePolicy Orchestrator=5.10.0-update_7
McAfee ePolicy Orchestrator=5.10.0-update_8
McAfee ePolicy Orchestrator=5.10.0-update_9
Event History
Oct 18, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-3338?
CVE-2022-3338 is an External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14.
2
How can CVE-2022-3338 lead to a Server Side Request Forgery attack?
CVE-2022-3338 can be exploited by mimicking the Agent Handler call to ePO and passing a carefully constructed XML file.
3
What is the severity of CVE-2022-3338?
CVE-2022-3338 has a severity score of 5.4, classified as medium.
4
Which versions of McAfee ePolicy Orchestrator are affected by CVE-2022-3338?
Versions of McAfee ePolicy Orchestrator prior to 5.10 Update 14 are affected.
5
How do I fix CVE-2022-3338?
To fix CVE-2022-3338, update ePO to version 5.10 Update 14 or later.