← All CVEs

CVE-2015-0922

medium · 5

McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.

5
CVSS
13.3%
EPSS (exploit prob.)
96th
EPSS percentile
2015-01-09
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
mcafeeepolicy_orchestrator<= 4.6.8
mcafeeepolicy_orchestrator5.0.0
mcafeeepolicy_orchestrator5.0.1
mcafeeepolicy_orchestrator5.1.0
mcafeeepolicy_orchestrator5.1.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-0922