CVE-2021-23890
McAfee ePO Information Leak vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows an unauthenticated user to download McAfee product packages (specifically McAfee Agent) available in ePO repository and install them on their own machines to have it managed and then in turn get policy details from the ePO server. This can only happen when the ePO Agent Handler is installed in a Demilitarized Zone (DMZ) to service machines not connected to the network through a VPN.
Una vulnerabilidad de filtrado de información en el controlador de agentes de McAfee ePolicy Orchestrator (ePO) versiones anteriores a 5.10 Update 10, permite a un usuario no autenticado descargar paquetes de productos de McAfee (específicamente McAfee Agent) disponibles en el repositorio de ePO e instalarlos en sus propios equipos para administrarlos y luego a su vez, obtener detalles de la política del servidor de ePO. Esto solo puede suceder cuando el controlador de agentes de ePO está instalado en una zona desmilitarizada (DMZ) para dar servicio a los equipos que no están conectados a la red mediante una VPN.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-12 CVE Reserved
- 2021-03-26 CVE Published
- 2023-12-10 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10352 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mcafee Search vendor "Mcafee" | Epolicy Orchestrator Search vendor "Mcafee" for product "Epolicy Orchestrator" | < 5.9.1 Search vendor "Mcafee" for product "Epolicy Orchestrator" and version " < 5.9.1" | - |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Epolicy Orchestrator Search vendor "Mcafee" for product "Epolicy Orchestrator" | 5.10.0 Search vendor "Mcafee" for product "Epolicy Orchestrator" and version "5.10.0" | - |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Epolicy Orchestrator Search vendor "Mcafee" for product "Epolicy Orchestrator" | 5.10.0 Search vendor "Mcafee" for product "Epolicy Orchestrator" and version "5.10.0" | update_1 |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Epolicy Orchestrator Search vendor "Mcafee" for product "Epolicy Orchestrator" | 5.10.0 Search vendor "Mcafee" for product "Epolicy Orchestrator" and version "5.10.0" | update_2 |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Epolicy Orchestrator Search vendor "Mcafee" for product "Epolicy Orchestrator" | 5.10.0 Search vendor "Mcafee" for product "Epolicy Orchestrator" and version "5.10.0" | update_3 |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Epolicy Orchestrator Search vendor "Mcafee" for product "Epolicy Orchestrator" | 5.10.0 Search vendor "Mcafee" for product "Epolicy Orchestrator" and version "5.10.0" | update_4 |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Epolicy Orchestrator Search vendor "Mcafee" for product "Epolicy Orchestrator" | 5.10.0 Search vendor "Mcafee" for product "Epolicy Orchestrator" and version "5.10.0" | update_5 |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Epolicy Orchestrator Search vendor "Mcafee" for product "Epolicy Orchestrator" | 5.10.0 Search vendor "Mcafee" for product "Epolicy Orchestrator" and version "5.10.0" | update_6 |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Epolicy Orchestrator Search vendor "Mcafee" for product "Epolicy Orchestrator" | 5.10.0 Search vendor "Mcafee" for product "Epolicy Orchestrator" and version "5.10.0" | update_7 |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Epolicy Orchestrator Search vendor "Mcafee" for product "Epolicy Orchestrator" | 5.10.0 Search vendor "Mcafee" for product "Epolicy Orchestrator" and version "5.10.0" | update_8 |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Epolicy Orchestrator Search vendor "Mcafee" for product "Epolicy Orchestrator" | 5.10.0 Search vendor "Mcafee" for product "Epolicy Orchestrator" and version "5.10.0" | update_9 |
Affected
|