CVE-2015-7310

UnknownEPSS 1.13%

Last modified

CVE-2015-7310 is a vulnerability of currently unknown severity. McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote authenticated users to execute arbitrary OS commands via a crafted filename, which is not properly handled when downloading the file.. EPSS estimates a 1.13% chance of exploitation in the next 30 days.

Description

McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote authenticated users to execute arbitrary OS commands via a crafted filename, which is not properly handled when downloading the file.

Metrics

EPSS Probability
1.13%

62.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
McafeeEnterprise Security Manager<= 9.3.2Mr17
McafeeEnterprise Security Manager<= 9.4.2Mr7
McafeeEnterprise Security Manager<= 9.5.0Mr6
McafeeEnterprise Security Manager\/Log Manager<= 9.3.2Mr17
McafeeEnterprise Security Manager\/Log Manager<= 9.4.2Mr7
McafeeEnterprise Security Manager\/Log Manager<= 9.5.0Mr6
McafeeEnterprise Security Manager\/Receiver<= 9.3.2Mr17
McafeeEnterprise Security Manager\/Receiver<= 9.4.2Mr7
McafeeEnterprise Security Manager\/Receiver<= 9.5.0Mr6

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-7310?
McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote authenticated users to execute arbitrary OS commands via a crafted filename, which is not properly handled when downloading the file.
How severe is CVE-2015-7310?
Severity scoring for CVE-2015-7310 is pending analysis. The EPSS model estimates a 1.13% probability of exploitation in the next 30 days.
How do I fix CVE-2015-7310?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-7310?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST