CVE-2012-2212: Medium severity McAfee Web Gateway vulnerability
DISPUTED McAfee Web Gateway 7.0 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher did not provide configuration details for the vulnerable system, and the observed behavior might be consistent with a configuration that was (perhaps inadvertently) designed to allow access based on Host HTTP headers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2212?
The severity of CVE-2012-2212 is disputed due to a lack of reproducibility in testing.
How do I fix CVE-2012-2212?
To fix CVE-2012-2212, ensure that your McAfee Web Gateway 7.0 is configured to validate the Host HTTP header properly.
Who is affected by CVE-2012-2212?
CVE-2012-2212 affects users of McAfee Web Gateway version 7.0.0.
What type of vulnerability is CVE-2012-2212?
CVE-2012-2212 is a vulnerability that allows attackers to bypass access controls via manipulation of the Host HTTP header.
Can CVE-2012-2212 be exploited remotely?
Yes, CVE-2012-2212 can be exploited remotely by attackers targeting the affected McAfee Web Gateway.