CVE Vulnerabilities

CVE-2022-0859

Insufficiently Protected Credentials

Published: Mar 23, 2022 | Modified: Nov 15, 2023
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during the restoration of the ePO server. To achieve this the attacker would have to be logged onto the server hosting the ePO server (restricted to administrators) and to know the SQL server password.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Epolicy_orchestrator Mcafee 5.10.0 5.10.0
Epolicy_orchestrator Mcafee 5.10.0 5.10.0
Epolicy_orchestrator Mcafee 5.10.0 5.10.0
Epolicy_orchestrator Mcafee 5.10.0 5.10.0
Epolicy_orchestrator Mcafee 5.10.0 5.10.0
Epolicy_orchestrator Mcafee 5.10.0 5.10.0
Epolicy_orchestrator Mcafee 5.10.0 5.10.0
Epolicy_orchestrator Mcafee * *
Epolicy_orchestrator Mcafee 5.10.0 5.10.0
Epolicy_orchestrator Mcafee 5.10.0 5.10.0
Epolicy_orchestrator Mcafee 5.10.0 5.10.0
Epolicy_orchestrator Mcafee 5.10.0 5.10.0
Epolicy_orchestrator Mcafee 5.10.0 5.10.0
Epolicy_orchestrator Mcafee 5.10.0 5.10.0

Potential Mitigations

References