CVE-2024-5955
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-5955 is a cross-site scripting (XSS) vulnerability affecting Trellix ePolicy Orchestrator versions prior to 5.10 Service Pack 1 Update 3. This issue enables a remote, authenticated attacker to inject malicious scripts into the response when accessing the ePolicy Orchestrator. Successful exploitation could lead to unintended execution of malicious code, potentially resulting in data theft or unauthorized account access. It is crucial for organizations using these affected versions of the ePolicy Orchestrator to apply the necessary updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.