McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers’ installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0922
Reference (s):
- BID:72298
- URL: http://www.securityfocus.com/bid/72298
- https://kc.mcafee.com/corporate/index?page=content&id=SB10095
- FULLDISC:20150106 McAfee ePolicy Orchestrator Authenticated XXE and Credential Exposure
- URL: http://seclists.org/fulldisclosure/2015/Jan/8

