Information Disclosure vulnerability in the Agent Handler in McAfee ePolicy Orchestrator (ePO) 5.9.x and 5.10.0 prior to 5.10.0 update 4 allows remote unauthenticated attacker to view sensitive information in plain text via sniffing the traffic between the Agent Handler and the SQL server.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Epolicy_orchestrator | Mcafee | 5.9.0 (including) | 5.9.0 (including) |
Epolicy_orchestrator | Mcafee | 5.9.1 (including) | 5.9.1 (including) |
Epolicy_orchestrator | Mcafee | 5.10.0 (including) | 5.10.0 (including) |
Epolicy_orchestrator | Mcafee | 5.10.0-update_1 (including) | 5.10.0-update_1 (including) |
Epolicy_orchestrator | Mcafee | 5.10.0-update_2 (including) | 5.10.0-update_2 (including) |
Epolicy_orchestrator | Mcafee | 5.10.0-update_3 (including) | 5.10.0-update_3 (including) |