Mcafee Web Gateway vulnerabilities

10 known vulnerabilities affecting mcafee/mcafee_web_gateway.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH1MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2020-7297MEDIUMCVSS 5.7≥ unspecified, < 9.2.12020-09-16
CVE-2020-7297 [MEDIUM] CWE-287 CVE-2020-7297: Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated u Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected dashboard data via improper access control in the user interface.
cvelistv5nvd
CVE-2020-7293CRITICALCVSS 9.0≥ unspecified, < 9.2.12020-09-15
CVE-2020-7293 [CRITICAL] CWE-287 CVE-2020-7293: Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated u Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change the system's root password via improper access controls in the user interface.
cvelistv5nvd
CVE-2020-7294MEDIUMCVSS 4.6≥ unspecified, < 9.2.12020-09-15
CVE-2020-7294 [MEDIUM] CWE-287 CVE-2020-7294: Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated u Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected files via improper access controls in the REST interface.
cvelistv5nvd
CVE-2020-7296MEDIUMCVSS 5.7≥ unspecified, < 9.2.12020-09-15
CVE-2020-7296 [MEDIUM] CWE-287 CVE-2020-7296: Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated u Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected configuration files via improper access control in the user interface.
cvelistv5nvd
CVE-2020-7295MEDIUMCVSS 4.6≥ unspecified, < 9.2.12020-09-15
CVE-2020-7295 [MEDIUM] CWE-287 CVE-2020-7295: Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated u Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected log data via improper access controls in the user interface.
cvelistv5nvd
CVE-2020-7292MEDIUMCVSS 4.3≥ unspecified, < 9.2.12020-07-15
CVE-2020-7292 [MEDIUM] CWE-838 CVE-2020-7292: Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 a Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attacker to cause MWG to return an ambiguous redirect response via getting a user to click on a malicious URL.
cvelistv5nvd
CVE-2019-3581HIGHCVSS 7.5≥ 7.8.2.0, < 7.8.2.5≥ 8.0.0.0, < 8.0.2.0+4 more2019-01-09
CVE-2019-3581 [HIGH] CWE-20 CVE-2019-3581: Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remo Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to cause a denial of service via a crafted HTTP request parameter.
cvelistv5nvd
CVE-2018-6678CRITICALCVSS 9.1v7.8.1.0≥ 7.8.1, < 7.8.1*2018-07-23
CVE-2018-6678 [CRITICAL] CVE-2018-6678: Configuration/Environment manipulation vulnerability in the administrative interface in McAfee Web G Configuration/Environment manipulation vulnerability in the administrative interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows authenticated administrator users to execute arbitrary commands via unspecified vectors.
cvelistv5nvd
CVE-2018-6677CRITICALCVSS 9.1v7.8.1.0≥ 7.8.1, < 7.8.1*2018-07-23
CVE-2018-6677 [CRITICAL] CWE-22 CVE-2018-6677: Directory Traversal vulnerability in the administrative user interface in McAfee Web Gateway (MWG) M Directory Traversal vulnerability in the administrative user interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows authenticated administrator users to gain elevated privileges via unspecified vectors.
cvelistv5nvd
CVE-2018-6667CRITICALCVSS 9.8≥ 7.8.1.0, ≤ 7.8.1.52018-06-26
CVE-2018-6667 [CRITICAL] CWE-287 CVE-2018-6667: Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1 Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attackers to execute arbitrary code via Java management extensions (JMX).
nvd