CVE-2018-6671: McAfee Epolicy Orchestrator
Medium severity, CVSS 6.5. EPSS: 2.6% chance of exploitation in the next 30 days.
Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticated users to bypass localhost only access security protection for some ePO features via a specially crafted HTTP request.
Affected products
- McAfee Epolicy Orchestrator: from 5.3.0, up to and including 5.3.3; from 5.9.0, up to and including 5.9.1
Published 2018-06-15. Last modified 2026-06-17.