Hardcoded Credentials Vulnerability in Trellix ePolicy Orchestrator
CVE-2024-4844
What is CVE-2024-4844?
A hardcoded credentials vulnerability exists in Trellix ePolicy Orchestrator (ePO) on Premise versions prior to 5.10 Service Pack 1 Update 2. This vulnerability enables an attacker with administrative privileges on the ePO server to potentially access sensitive information, specifically the contents of the orion.keystore file. By exploiting a hardcoded password associated with this keystore, the attacker could retrieve the database encryption key, compromising data integrity and confidentiality. The exploit requires the attacker to be in a position of elevated privileges on the system, limiting exposure to system administrators.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ePolicy Orchestrator Windows All versions below ePO 5.10 Service Pack 1 Update 2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
