CVE-2023-5445
An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter for the purpose of redirecting URL request(s) to a malicious site. This impacts the dashboard area of the user interface. A user would need to be logged into ePO to trigger this vulnerability. To exploit this the attacker must change the HTTP payload post submission, prior to it reaching the ePO server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5445?
The severity of CVE-2023-5445 is medium with a CVSS score of 5.4.
How does CVE-2023-5445 impact ePolicy Orchestrator?
CVE-2023-5445 allows a remote low privileged user to modify the URL parameter and redirect URL requests to a malicious site in ePolicy Orchestrator.
Which versions of ePolicy Orchestrator are affected by CVE-2023-5445?
CVE-2023-5445 affects McAfee ePolicy Orchestrator versions up to 5.10.0 CP1 Update 2.
How can I fix CVE-2023-5445?
To fix CVE-2023-5445, users should update to ePolicy Orchestrator version 5.10.0 CP1 Update 2 or later.
Where can I find more information about CVE-2023-5445?
You can find more information about CVE-2023-5445 at the following link: [https://kcm.trellix.com/corporate/index?page=content&id=SB10410](https://kcm.trellix.com/corporate/index?page=content&id=SB10410).