APP: McAfee ePolicy Orchestrator
This signature detects attempts to exploit a known vulnerability against McAfee ePolicy Orchestrator prior to version 3.5.5.438. A successful attack can lead to arbitrary code execution.
Extended Description
The McAfee ePolicy Orchestrator framework service is prone to a directory-traversal vulnerability that can lead to complete system compromise.. The application fails to sanitize user input when accepting POST requests on the '/spipe/pkg' interface. Specifically, the script fails to sanitize input for proper directory and filename, allowing an attacker to conduct a directory-traversal attack that can overwrite existing files or place arbitrary files on a vulnerable computer. A successful exploit may allow unauthorized remote users to overwrite existing files or place arbitrary files on a vulnerable computer.
Affected Products
Mcafee epolicy_orchestrator
References
BugTraq: 18979
CVE: CVE-2006-3623
URL: http://www.eeye.com/html/research/advisories/AD20060713.html http://www.frsirt.com/english/advisories/2006/2796
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Mcafee
5.0