QID 376631

Date Published: 2022-05-25

QID 376631: McAfee MA Agent ePO extension SQL Injection Vulnerability (SB10382)

The McAfee Agent is the distributed component of McAfee ePolicy Orchestrator. It downloads and enforces policies, and executes client-side tasks such as deployment and updating. The Agent also uploads events and provides additional data regarding each system status.

CVE-2022-1258: Blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be exploited by an authenticated administrator on ePO to perform arbitrary SQL queries in the back-end database.

Affected versions:
McAfee Agent Prior to 5.7.6
QID Detection Logic(Authenticated):
This checks for vulnerable version of McAFee MA (EPOAGENTMETA) ePo extension .

Successful exploitation of this vulnerability may allow an authenticated attacker to execute arbitrary SQL queries on the target system.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as High - 6 severity.
  • Solution
    Install or update to McAfee Agent 5.7.6 For more details refer SB10382

    CVEs related to QID 376631

    Software Advisories
    Advisory ID Software Component Link
    SB10382 URL Logo kc.mcafee.com/corporate/index?page=content&id=SB10382