Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-3936


OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run arbitrary OS commands with limited privileges via not sanitizing the user input data before exporting it into a CSV format output.


Published

2018-06-13T21:29:00.440

Last Modified

2024-11-21T03:26:21.850

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.2 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mcafee epolicy_orchestrator 5.1.0 Yes
Application mcafee epolicy_orchestrator 5.1.1 Yes
Application mcafee epolicy_orchestrator 5.1.2 Yes
Application mcafee epolicy_orchestrator 5.1.3 Yes
Application mcafee epolicy_orchestrator 5.3.1 Yes
Application mcafee epolicy_orchestrator 5.3.2 Yes
Application mcafee epolicy_orchestrator 5.9.0 Yes

References