CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 3.5. It may be remotely exploitable.
CVE
CVE-2022-0861
Severity
LOW
CVSS
3.5
EPSS
0.45%
Original NVD Description
A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality. The impact is limited to some access to confidential information and some ability to alter data.
Related CVEs
Other vulnerabilities affecting the same vendor(s)