VulnerabilityModified
CVE-2006-3623
Directory traversal vulnerability in Framework Service component in McAfee ePolicy Orchestrator agent 3.5.0.x and earlier allows remote attackers to create arbitrary files via a ..
MEDIUM 5.0EPSS 1.87%
Does this matter?
Lower severity and a low EPSS score (1.87%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Framework Service component in McAfee ePolicy Orchestrator agent 3.5.0.x and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the directory and filename in a PropsResponse (PackageType) request.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.87% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- mcafee/epolicy orchestrator agent
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21037Vendor Advisory
- http://securitytracker.com/id?1016501
- http://www.eeye.com/html/research/advisories/AD20060713.htmlExploit
- http://www.osvdb.org/27158
- http://www.securityfocus.com/archive/1/440077/100/0/threaded
- http://www.securityfocus.com/bid/18979
- http://www.vupen.com/english/advisories/2006/2796
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27738
- http://secunia.com/advisories/21037Vendor Advisory
- http://securitytracker.com/id?1016501
- http://www.eeye.com/html/research/advisories/AD20060713.htmlExploit
- http://www.osvdb.org/27158
- http://www.securityfocus.com/archive/1/440077/100/0/threaded
- http://www.securityfocus.com/bid/18979
- http://www.vupen.com/english/advisories/2006/2796
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27738
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.