Vulnerability Description
OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run arbitrary OS commands with limited privileges via not sanitizing the user input data before exporting it into a CSV format output.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Epolicy Orchestrator | 5.1.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/103155
- https://kc.mcafee.com/corporate/index?page=content&id=SB10227
- http://www.securityfocus.com/bid/103155
- https://kc.mcafee.com/corporate/index?page=content&id=SB10227
FAQ
What is CVE-2017-3936?
CVE-2017-3936 is a vulnerability with a CVSS score of 6.2 (MEDIUM). OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run arbitrary OS commands with limited privileges via no...
How severe is CVE-2017-3936?
CVE-2017-3936 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-3936?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Epolicy Orchestrator.