CVE-2024-5955: Trellix Epo Onprem SP1 UPDATE4
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a remote authenticated attacker to craft requests causing arbitrary content to be injected into the response when accessing the epolicy Orchestrator.
Affected products
- Trellix Epo Onprem SP1 UPDATE4
Published 2024-12-20. Last modified 2026-06-17.