CVE-2015-2859
Last modified
CVE-2015-2859 is a vulnerability of currently unknown severity. Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certification Authority names in X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.. EPSS estimates a 1.02% chance of exploitation in the next 30 days.
Description
Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certification Authority names in X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Epolicy Orchestrator | 4.0 |
| Mcafee | Epolicy Orchestrator | 4.5.0 |
| Mcafee | Epolicy Orchestrator | 4.5.3 |
| Mcafee | Epolicy Orchestrator | 4.5.4 |
| Mcafee | Epolicy Orchestrator | 4.5.5 |
| Mcafee | Epolicy Orchestrator | 4.5.6 |
| Mcafee | Epolicy Orchestrator | 4.5.7 |
| Mcafee | Epolicy Orchestrator | 4.6.0 |
| Mcafee | Epolicy Orchestrator | 4.6.1 |
| Mcafee | Epolicy Orchestrator | 4.6.2 |
| Mcafee | Epolicy Orchestrator | 4.6.3 |
| Mcafee | Epolicy Orchestrator | 4.6.4 |
| Mcafee | Epolicy Orchestrator | 4.6.5 |
| Mcafee | Epolicy Orchestrator | 4.6.6 |
| Mcafee | Epolicy Orchestrator | 4.6.7 |
| Mcafee | Epolicy Orchestrator | 4.6.8 |
| Mcafee | Epolicy Orchestrator | 4.6.9 |
| Mcafee | Epolicy Orchestrator | 5.0.0 |
| Mcafee | Epolicy Orchestrator | 5.0.1 |
| Mcafee | Epolicy Orchestrator | 5.1.0 |
| Mcafee | Epolicy Orchestrator | 5.1.1 |
| Mcafee | Epolicy Orchestrator | 5.1.2 |
References
- http://www.kb.cert.org/vuls/id/264092Third Party Advisory, US Government Resource
- https://kc.mcafee.com/corporate/index?page=content&id=KB84628Patch, Vendor Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10120Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/264092Third Party Advisory, US Government Resource
- https://kc.mcafee.com/corporate/index?page=content&id=KB84628Patch, Vendor Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10120Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-2859?
How severe is CVE-2015-2859?
How do I fix CVE-2015-2859?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-2853Session fixation vulnerability in the WebUI component in Blu…
- CVE-2015-2854The WebUI component in Blue Coat SSL Visibility Appliance SV…
- CVE-2015-2855The WebUI component in Blue Coat SSL Visibility Appliance SV…
- CVE-2015-2856Directory traversal vulnerability in the template function i…
- CVE-2015-2857Accellion File Transfer Appliance before FTA_9_11_210 allows…9.8
- CVE-2015-2858Datalex airline booking software before 2015-09-03 allows re…
- CVE-2015-2860Directory traversal vulnerability in Avigilon Control Center…
- CVE-2015-2861Cross-site request forgery (CSRF) vulnerability in Vesta Con…
- CVE-2015-2862Directory traversal vulnerability in Kaseya Virtual System A…
- CVE-2015-2863Open redirect vulnerability in Kaseya Virtual System Adminis…
- CVE-2015-2864Retrospect and Retrospect Client before 10.0.2.119 on Window…
- CVE-2015-2865Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
Are you affected by CVE-2015-2859?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
