First published: Tue Oct 18 2022(Updated: )
An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and passing the carefully constructed XML file through the API.
Credit: trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee ePolicy Orchestrator | <5.10.0 | |
McAfee ePolicy Orchestrator | =5.10.0 | |
McAfee ePolicy Orchestrator | =5.10.0-update_1 | |
McAfee ePolicy Orchestrator | =5.10.0-update_10 | |
McAfee ePolicy Orchestrator | =5.10.0-update_11 | |
McAfee ePolicy Orchestrator | =5.10.0-update_12 | |
McAfee ePolicy Orchestrator | =5.10.0-update_13 | |
McAfee ePolicy Orchestrator | =5.10.0-update_2 | |
McAfee ePolicy Orchestrator | =5.10.0-update_3 | |
McAfee ePolicy Orchestrator | =5.10.0-update_4 | |
McAfee ePolicy Orchestrator | =5.10.0-update_5 | |
McAfee ePolicy Orchestrator | =5.10.0-update_6 | |
McAfee ePolicy Orchestrator | =5.10.0-update_7 | |
McAfee ePolicy Orchestrator | =5.10.0-update_8 | |
McAfee ePolicy Orchestrator | =5.10.0-update_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3338 is an External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14.
CVE-2022-3338 can be exploited by mimicking the Agent Handler call to ePO and passing a carefully constructed XML file.
CVE-2022-3338 has a severity score of 5.4, classified as medium.
Versions of McAfee ePolicy Orchestrator prior to 5.10 Update 14 are affected.
To fix CVE-2022-3338, update ePO to version 5.10 Update 14 or later.