cbcvebase.
CVE-2015-0922
published 2015-01-09

CVE-2015-0922: McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers…

PriorityP340medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
13.35%
95.9th percentile
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.

Affected

5 ranges
VendorProductVersion rangeFixed in
mcafeeepolicy_orchestrator<= 4.6.8
mcafeeepolicy_orchestrator
mcafeeepolicy_orchestrator
mcafeeepolicy_orchestrator
mcafeeepolicy_orchestrator
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.