CVE-2018-6671
Last modified
CVE-2018-6671 is a vulnerability of currently unknown severity. Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticated users to bypass localhost only access security protection for some ePO features via a specially crafted HTTP request.. EPSS estimates a 4.70% chance of exploitation in the next 30 days.
Description
Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticated users to bypass localhost only access security protection for some ePO features via a specially crafted HTTP request.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Epolicy Orchestrator | >= 5.3.0, <= 5.3.3 |
| Mcafee | Epolicy Orchestrator | >= 5.9.0, <= 5.9.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-6671?
How severe is CVE-2018-6671?
How do I fix CVE-2018-6671?
Are you affected by CVE-2018-6671?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
