First published: Fri Nov 17 2023(Updated: )
A Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2 allows a remote low privilege user to successfully add a new user with administrator privileges to the ePO server. This impacts the dashboard area of the user interface. To exploit this the attacker must change the HTTP payload post submission, prior to it reaching the ePO server.
Credit: trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee ePolicy Orchestrator | <5.10.0 | |
McAfee ePolicy Orchestrator | =5.10.0-service_pack_1_update | |
McAfee ePolicy Orchestrator | =5.10.0-service_pack_1_update_1 | |
McAfee ePolicy Orchestrator | =5.10.0-update_1 | |
McAfee ePolicy Orchestrator | =5.10.0-update_10 | |
McAfee ePolicy Orchestrator | =5.10.0-update_11 | |
McAfee ePolicy Orchestrator | =5.10.0-update_11_hotfix_1 | |
McAfee ePolicy Orchestrator | =5.10.0-update_11_hotfix_2 | |
McAfee ePolicy Orchestrator | =5.10.0-update_12 | |
McAfee ePolicy Orchestrator | =5.10.0-update_13 | |
McAfee ePolicy Orchestrator | =5.10.0-update_14 | |
McAfee ePolicy Orchestrator | =5.10.0-update_15 | |
McAfee ePolicy Orchestrator | =5.10.0-update_2 | |
McAfee ePolicy Orchestrator | =5.10.0-update_3 | |
McAfee ePolicy Orchestrator | =5.10.0-update_4 | |
McAfee ePolicy Orchestrator | =5.10.0-update_5 | |
McAfee ePolicy Orchestrator | =5.10.0-update_6 | |
McAfee ePolicy Orchestrator | =5.10.0-update_7 | |
McAfee ePolicy Orchestrator | =5.10.0-update_8 | |
McAfee ePolicy Orchestrator | =5.10.0-update_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this CSRF vulnerability is CVE-2023-5444.
The severity of CVE-2023-5444 is high (8 out of 10).
The ePolicy Orchestrator version prior to 5.10.0 CP1 Update 2 is affected by CVE-2023-5444.
To exploit this vulnerability, the attacker must perform a Cross Site Request Forgery attack.
Yes, the fix for CVE-2023-5444 is to update ePolicy Orchestrator to version 5.10.0 CP1 Update 2 or later.