PT-2021-15587 · Mcafee · Mcafee Web Gateway
Published
2021-02-17
·
Updated
2022-04-26
·
CVE-2021-23885
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
McAfee Web Gateway versions prior to 9.2.8
Description:
The issue allows an authenticated user to gain elevated privileges through the User Interface and execute commands on the appliance. This is due to incorrect improper neutralization of user input in the troubleshooting page.
Recommendations:
For versions prior to 9.2.8, update to version 9.2.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the troubleshooting page to minimize the risk of exploitation.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcafee Web Gateway