Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.805595
Kategorie:Web application abuses
Titel:McAfee ePolicy Orchestrator Man-in-the-Middle Attack Vulnerability - June15
Zusammenfassung:This host is installed with McAfee ePolicy; Orchestrator and is prone to man-in-the-middle attack vulnerability.
Beschreibung:Summary:
This host is installed with McAfee ePolicy
Orchestrator and is prone to man-in-the-middle attack vulnerability.

Vulnerability Insight:
The flaw exists as the application fails to
properly validate SSL/TLS certificates

Vulnerability Impact:
Successful exploitation will allow remote
attacker to intercept and manipulate HTTPS traffic between the ePO application
and registered servers.

Affected Software/OS:
McAfee ePolicy Orchestrator version 4.x
through 4.6.9 and 5.x through 5.1.2

Solution:
Upgrade to McAfee ePolicy Orchestrator
version 4.6.9 or 5.1.2 or later, and then apply the manual settings listed the
referenced KB article of the vendor.

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2015-2859
BugTraq ID: 75020
http://www.securityfocus.com/bid/75020
CERT/CC vulnerability note: VU#264092
http://www.kb.cert.org/vuls/id/264092
http://www.securitytracker.com/id/1032571
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.