VulnerabilityModified
CVE-2014-2205
The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External…
MEDIUM 6.3EPSS 2.00%
Does this matter?
Lower severity and a low EPSS score (2.00%). Track it; it rarely justifies an emergency change on its own.
Description
The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External Entity (XXE) issue.
- CVSS 2.0
- 6.3 MEDIUMAV:N/AC:M/Au:S/C:C/I:N/A:N
- EPSS
- 2.00% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- mcafee/epolicy orchestrator
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/57114Vendor Advisory
- http://www.securityfocus.com/archive/1/531255/100/0/threaded
- http://www.securityfocus.com/bid/65771
- https://kc.mcafee.com/corporate/index?page=content&id=SB10065Vendor Advisory
- https://www.redteam-pentesting.de/advisories/rt-sa-2014-001.txtExploit
- http://secunia.com/advisories/57114Vendor Advisory
- http://www.securityfocus.com/archive/1/531255/100/0/threaded
- http://www.securityfocus.com/bid/65771
- https://kc.mcafee.com/corporate/index?page=content&id=SB10065Vendor Advisory
- https://www.redteam-pentesting.de/advisories/rt-sa-2014-001.txtExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.