CVE-2024-4843
ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow a least privileged user to manipulate the client task and client task assignments, hence escalating his/her privilege.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4843?
CVE-2024-4843 is classified as a medium severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2024-4843?
To fix CVE-2024-4843, ensure that access controls are appropriately configured to prevent least privileged users from manipulating client tasks and assignments.
Who is affected by CVE-2024-4843?
CVE-2024-4843 affects users of McAfee ePolicy Orchestrator who may have been granted regular privileged user roles.
What are the implications of CVE-2024-4843?
The implications of CVE-2024-4843 include unauthorized privilege escalation, allowing a lower-privileged user to delete tasks or manipulate assignments.
When was CVE-2024-4843 discovered?
CVE-2024-4843 was published in 2024, highlighting its relevance to recent vulnerabilities in McAfee ePolicy Orchestrator.