SSL: McAfee ePolicy Orchestrator XML External Entity

This signature detects attempts to exploit a known flaw in the McAfee ePolicy Orchestrato. A successful attack may result in data exposure and/or arbitrary command injection.

Extended Description

The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to add dashboards to read arbitrary files by importing a crafted XML file, related to an XML External Entity (XXE) issue.

Affected Products

Mcafee epolicy_orchestrator

References

BugTraq: 65771

CVE: CVE-2014-2205

Short Name
SSL:MCAFEE-EPOLICY-XML
Severity
Major
Recommended
False
Recommended Action
Drop
Category
SSL
Keywords
CVE-2014-2205 Entity External McAfee Orchestrator XML bid:65771 ePolicy
Release Date
05/07/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Mcafee

CVSS Score

6.3

Found a potential security threat?