Vulnerability Description
Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Epolicy Orchestrator | 2.5.1 |
References
- http://secunia.com/advisories/8311
- http://www.atstake.com/research/advisories/2003/a031703-1.txtExploitPatchVendor Advisory
- http://www.osvdb.org/4375
- http://www.securityfocus.com/archive/1/315230/30/25490/threaded
- http://www.securityfocus.com/bid/7111PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11559
- http://secunia.com/advisories/8311
- http://www.atstake.com/research/advisories/2003/a031703-1.txtExploitPatchVendor Advisory
- http://www.osvdb.org/4375
- http://www.securityfocus.com/archive/1/315230/30/25490/threaded
- http://www.securityfocus.com/bid/7111PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11559
FAQ
What is CVE-2002-0690?
CVE-2002-0690 is a vulnerability with a CVSS score of 10.0 (HIGH). Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings.
How severe is CVE-2002-0690?
CVE-2002-0690 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0690?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Epolicy Orchestrator.