VYPR
High severity7.2NVD Advisory· Published May 18, 2017· Updated May 13, 2026

CVE-2017-3980

CVE-2017-3980

Description

A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 and earlier allows remote authenticated users to execute a command of their choice via an authenticated ePO session.

Affected products

2
  • cpe:2.3:a:mcafee:epolicy_orchestrator:*:*:*:*:*:*:*:*
    Range: <=5.1.3
  • McAfee/ePolicy Orchestrator (ePO)v5
    Range: 5.9.0 and earlier

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.