HomeMcafeeCVE-2022-0859

CVE-2022-0859

MEDIUM
6.5CVSS
Published: 2022-03-23
Updated: 2024-11-21
AI Analysis

Description

McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during the restoration of the ePO server. To achieve this the attacker would have to be logged onto the server hosting the ePO server (restricted to administrators) and to know the SQL server password.

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Vector
local
Complexity
low
Privileges
high
User Action
required
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-522CWE-522

Metadata

Primary Vendor
MCAFEE
Published
3/23/2022
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

mcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestratormcafee : epolicy_orchestrator

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2022-0859 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com