CVE-2015-2859
5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD
Description
Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certification Authority names in X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected (22)
Products: Mcafee: Epolicy Orchestrator
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
Related CWEs
References (10)
Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: cret@cert.org
Source: cret@cert.org
Source: cret@cert.org
PatchVendor Advisory
Source: cret@cert.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.