CVE-2015-7310: McAfee Enterprise Security Manager
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote authenticated users to execute arbitrary OS commands via a crafted filename, which is not properly handled when downloading the file.
Affected products
- McAfee Enterprise Security Manager: up to and including 9.3.2; up to and including 9.4.2; up to and including 9.5.0
- McAfee Enterprise Security Manager/log Manager: up to and including 9.3.2; up to and including 9.4.2; up to and including 9.5.0
- McAfee Enterprise Security Manager/receiver: up to and including 9.3.2; up to and including 9.4.2; up to and including 9.5.0
Published 2015-09-22. Last modified 2026-06-17.