PT-2021-15586 · Mcafee · Mcafee Content Security Reporter+2

Published

2021-04-15

·

Updated

2023-11-16

·

CVE-2021-23884

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: McAfee Content Security Reporter (CSR) versions prior to 2.8.0
Description: The issue allows an ePO administrator to view unencrypted passwords of the McAfee Web Gateway (MWG) or the McAfee Web Gateway Cloud Server (MWGCS) read-only user. This occurs due to a cleartext transmission of sensitive information vulnerability in the ePO Extension of McAfee Content Security Reporter (CSR).
Recommendations: For versions prior to 2.8.0, update to version 2.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the ePO administrator role to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2021-23884

Affected Products

Mcafee Content Security Reporter
Mcafee Web Gateway
Mcafee Web Gateway Cloud Server