CVE-2015-2859: McAfee Epolicy Orchestrator

Medium severity, CVSS 5.8. EPSS: 1% chance of exploitation in the next 30 days.

Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certification Authority names in X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Affected products

  • McAfee Epolicy Orchestrator: version 4.0 only; version 4.5.0 only; version 4.5.3 only; version 4.5.4 only; version 4.5.5 only; version 4.5.6 only; …

Published 2015-06-23. Last modified 2026-06-17.