CVE-2024-5955: XSS
Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a remote authenticated attacker to craft requests causing arbitrary content to be injected into the response when accessing the epolicy Orchestrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5955?
CVE-2024-5955 is considered a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2024-5955?
To fix CVE-2024-5955, upgrade Trellix ePolicy Orchestrator to version 5.10 Service Pack 1 Update 3 or later.
Who is affected by CVE-2024-5955?
CVE-2024-5955 affects users of Trellix ePolicy Orchestrator versions prior to 5.10 Service Pack 1 Update 3.
What type of vulnerability is CVE-2024-5955?
CVE-2024-5955 is a cross-site scripting (XSS) vulnerability.
What are the implications of CVE-2024-5955?
The implications of CVE-2024-5955 include the potential for attackers to inject arbitrary content into the ePolicy Orchestrator responses.