Vulnerabilities
Vulnerable Software
Mcafee:  Security Vulnerabilities
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.
CVSS Score
5.0
EPSS Score
0.457
Published
2015-01-09
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orionUpdateTableFilter.do.
CVSS Score
4.0
EPSS Score
0.582
Published
2015-01-09
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to execute arbitrary code via vectors related to ICMP redirection.
CVSS Score
7.5
EPSS Score
0.03
Published
2014-10-29
Unspecified vulnerability in the login form in McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to cause a denial of service via a crafted value in the domain field.
CVSS Score
2.1
EPSS Score
0.001
Published
2014-10-29
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to bypass intended restriction on unspecified functionality via unknown vectors.
CVSS Score
4.6
EPSS Score
0.001
Published
2014-10-29
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading unspecified error messages.
CVSS Score
2.1
EPSS Score
0.001
Published
2014-10-29
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading the logs.
CVSS Score
2.1
EPSS Score
0.001
Published
2014-10-29
The (1) Removable Media and (2) CD and DVD encryption offsite access options (formerly Endpoint Encryption for Removable Media or EERM) in McAfee File and Removable Media Protection (FRP) 4.3.0.x, and Endpoint Encryption for Files and Folders (EEFF) 3.2.x through 4.2.x, uses a hard-coded salt, which makes it easier for local users to obtain passwords via a brute force attack.
CVSS Score
2.1
EPSS Score
0.0
Published
2014-10-29
Unspecified vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to read arbitrary files via unknown vectors.
CVSS Score
2.1
EPSS Score
0.001
Published
2014-10-29
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information via vectors related to open network ports.
CVSS Score
5.0
EPSS Score
0.005
Published
2014-10-29


Contact Us

Shodan ® - All rights reserved