Arbitrary Command Execution Vulnerability in McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3

Arbitrary Command Execution Vulnerability in McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3

CVE-2004-0038 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.

Learn more about our Web Application Penetration Testing UK.