cve/2018/CVE-2018-6671.md

21 lines
1.0 KiB
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2018-6671](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6671)
![](https://img.shields.io/static/v1?label=Product&message=ePolicy%20Orchestrator%20(ePO)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=5.3.0%20through%205.3.35.3.3%20with%20hotfix%20EPO5xHF1229850%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Application%20Protection%20Bypass%20vulnerability%0A&color=brighgreen)
### Description
Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticated users to bypass localhost only access security protection for some ePO features via a specially crafted HTTP request.
### POC
#### Reference
- https://kc.mcafee.com/corporate/index?page=content&id=SB10240
2024-06-09 00:33:16 +00:00
- https://kc.mcafee.com/corporate/index?page=content&id=SB10240
2024-05-26 14:27:05 +02:00
- https://www.exploit-db.com/exploits/46518/
2024-06-09 00:33:16 +00:00
- https://www.exploit-db.com/exploits/46518/
2024-05-26 14:27:05 +02:00
#### Github
- https://github.com/ARPSyndicate/cvemon