CVE-2017-3936
Summary
| CVE | CVE-2017-3936 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-13 21:29:00 UTC |
| Updated | 2023-11-07 02:44:00 UTC |
| Description | OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run arbitrary OS commands with limited privileges via not sanitizing the user input data before exporting it into a CSV format output. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Epolicy Orchestrator | 5.1.0 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.1 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.2 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.3 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.3.1 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.3.2 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.9.0 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.0 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.1 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.2 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.1.3 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.3.1 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.3.2 | All | All | All |
| Application | Mcafee | Epolicy Orchestrator | 5.9.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| McAfee Security Bulletin - ePolicy Orchestrator update fixes possible blind command injection vulnerability (CVE-2017-3936) | kc.mcafee.com | ||
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.