Information Disclosure Vulnerability in McAfee ePolicy Orchestrator
CVE-2019-3619
6.8MEDIUM
Key Information:
- Vendor
- Mcafee, Llc
- Status
- Mcafee Epolicy Orchestrator (epo)
- Vendor
- CVE Published:
- 3 July 2019
Summary
The Agent Handler in McAfee ePolicy Orchestrator is susceptible to an information disclosure vulnerability. This issue allows remote unauthenticated attackers to intercept and view sensitive information transmitted in plain text between the Agent Handler and the SQL server. Attackers can exploit this vulnerability by sniffing network traffic, which may lead to unauthorized access to critical data.
Affected Version(s)
McAfee ePolicy Orchestrator (ePO) 5.9.x and 5.10.0 < 5.10.0 Update 4
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved