CVE-2015-8988

Unquoted executable path vulnerability in Client Management and Gateway components in McAfee (now Intel Security) ePO Deep Command (eDC) 2.2 and 2.1 allows authenticated users to execute a command of their choice via dropping a malicious file for the path.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:epo_deep_command:2.1:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:epo_deep_command:2.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-03-14 22:59

Updated : 2024-02-28 15:44


NVD link : CVE-2015-8988

Mitre link : CVE-2015-8988

CVE.ORG link : CVE-2015-8988


JSON object : View

Products Affected

mcafee

  • epo_deep_command
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')