CVE-2008-1855 describes a remote denial-of-service vulnerability affecting McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, utilized by ePolicy Orchestrator (ePO) and ProtectionPilot. Attackers can trigger a CMA Framework service crash by sending a long, invalid method within requests to the /spin//AVClient//AVClient.csp URI, leading to memory corruption. This vulnerability has a CVSS score of 5.0, indicating a medium severity. It is easily exploitable remotely with low attack complexity and no authentication required, resulting in a partial denial of service. The EPSS score is low, suggesting a low probability of exploitation in the wild. While not listed on the KEV catalog or Hot List, exploit code is publicly available on ExploitDB (EDB-5343). There is no evidence of active exploitation, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.6.0.574CPE matchmatch criteria | cpe:2.3:a:mcafee:cma:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.