CVE-2019-3619

6.8MEDIUM

Key Information:

Vendor
Mcafee, Llc
Status
Mcafee Epolicy Orchestrator (epo)
Vendor
CVE Published:
3 July 2019

Summary

Information Disclosure vulnerability in the Agent Handler in McAfee ePolicy Orchestrator (ePO) 5.9.x and 5.10.0 prior to 5.10.0 update 4 allows remote unauthenticated attacker to view sensitive information in plain text via sniffing the traffic between the Agent Handler and the SQL server.

Affected Version(s)

McAfee ePolicy Orchestrator (ePO) 5.9.x and 5.10.0 < 5.10.0 Update 4

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.