← Back

CVE-2023-5445

nvd nist
Published: Nov 17, 2023Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter for the purpose of redirecting URL request(s) to a malicious site. This impacts the dashboard area of the user interface. A user would need to be logged into ePO to trigger this vulnerability. To exploit this the attacker must change the HTTP payload post submission, prior to it reaching the ePO server.

Affected (20)

1 product
Epolicy Orchestrator
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Mcafee
Before 5.10.0
Version 5.10.0 service_pack_1_update
Version 5.10.0 service_pack_1_update_1
Version 5.10.0 update_10
Version 5.10.0 update_11
Version 5.10.0 update_11_hotfix_1
Version 5.10.0 update_11_hotfix_2
Version 5.10.0 update_12
Version 5.10.0 update_13
Version 5.10.0 update_14
Version 5.10.0 update_15
Version 5.10.0 update_1
Version 5.10.0 update_2
Version 5.10.0 update_3
Version 5.10.0 update_4
Version 5.10.0 update_5
Version 5.10.0 update_6
Version 5.10.0 update_7
Version 5.10.0 update_8
Version 5.10.0 update_9

References (2)

Source: trellixpsirt@trellix.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.