First published: Wed Jul 26 2023(Updated: )
A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session by convincing the authenticated ePO administrator to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO.
Credit: trellixpsirt@trellix.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee ePolicy Orchestrator | <5.10.0 | |
McAfee ePolicy Orchestrator | =5.10.0 | |
McAfee ePolicy Orchestrator | =5.10.0-update_1 | |
McAfee ePolicy Orchestrator | =5.10.0-update_10 | |
McAfee ePolicy Orchestrator | =5.10.0-update_11 | |
McAfee ePolicy Orchestrator | =5.10.0-update_11_hotfix_1 | |
McAfee ePolicy Orchestrator | =5.10.0-update_11_hotfix_2 | |
McAfee ePolicy Orchestrator | =5.10.0-update_12 | |
McAfee ePolicy Orchestrator | =5.10.0-update_13 | |
McAfee ePolicy Orchestrator | =5.10.0-update_14 | |
McAfee ePolicy Orchestrator | =5.10.0-update_15 | |
McAfee ePolicy Orchestrator | =5.10.0-update_2 | |
McAfee ePolicy Orchestrator | =5.10.0-update_3 | |
McAfee ePolicy Orchestrator | =5.10.0-update_4 | |
McAfee ePolicy Orchestrator | =5.10.0-update_5 | |
McAfee ePolicy Orchestrator | =5.10.0-update_6 | |
McAfee ePolicy Orchestrator | =5.10.0-update_7 | |
McAfee ePolicy Orchestrator | =5.10.0-update_8 | |
McAfee ePolicy Orchestrator | =5.10.0-update_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3946 is a reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1 that allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session.
CVE-2023-3946 affects McAfee ePolicy Orchestrator versions 5.10.0 through 5.10.0-update_15.
CVE-2023-3946 has a severity rating of 6.1 (medium).
An attacker can exploit CVE-2023-3946 by convincing an authenticated ePO administrator to click on a carefully crafted link.
You can find more information about CVE-2023-3946 at this link: [https://kcm.trellix.com/corporate/index?page=content&id=SB10402]