CVE-2022-3339: Reflected XSS in Trellix ePO server
A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 Update 14 allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session by convincing the authenticated ePO administrator to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-3339.
What is the severity of CVE-2022-3339?
The severity of CVE-2022-3339 is medium with a CVSS score of 6.1.
What software is affected by CVE-2022-3339?
The vulnerability affects McAfee ePolicy Orchestrator prior to version 5.10 Update 14.
How does CVE-2022-3339 work?
CVE-2022-3339 is a reflected cross-site scripting (XSS) vulnerability that allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session by convincing the authenticated ePO administrator to click on a carefully crafted link.
Is there a fix available for CVE-2022-3339?
Yes, a fix is available in ePolicy Orchestrator version 5.10 Update 14.