CVE-2024-4844 is a hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2. An attacker with administrative privileges on the ePO server can exploit a hardcoded password to read the orion.keystore file, thereby accessing the ePO database encryption key. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a high potential impact on confidentiality, integrity, and availability, though it requires high attack complexity and low privileges. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Trellix | EPolicy Orchestrator | All versions below ePO 5.10 Service Pack 1 Update 2CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.