CVE-2017-3980: McAfee Epolicy Orchestrator

High severity, CVSS 7.2. EPSS: 2.8% chance of exploitation in the next 30 days.

A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 and earlier allows remote authenticated users to execute a command of their choice via an authenticated ePO session.

Affected products

  • McAfee Epolicy Orchestrator: up to and including 5.1.3; from 5.3.0, up to and including 5.3.3; from 5.9.0, up to and including 5.9.1

Published 2017-05-18. Last modified 2026-06-17.