CVE-2024-5955: Trellix Epo Onprem SP1 UPDATE4

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a remote authenticated attacker to craft requests causing arbitrary content to be injected into the response when accessing the epolicy Orchestrator.

Affected products

Published 2024-12-20. Last modified 2026-06-17.