CVE-2014-6064: Infoleak
Published Sep 2, 2014
·Updated
The Accounts tab in the administrative user interface in McAfee Web Gateway (MWG) before 7.3.2.9 and 7.4.x before 7.4.2 allows remote authenticated users to obtain the hashed user passwords via unspecified vectors.
Affected Software
2 affected components
McAfee Web Gateway>=7.3.0<7.3.2.9
McAfee Web Gateway>=7.4.0<7.4.2
Event History
Sep 2, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6064?
CVE-2014-6064 has been rated as a medium severity vulnerability due to its potential to expose hashed user passwords.
2
How do I fix CVE-2014-6064?
To mitigate CVE-2014-6064, upgrade McAfee Web Gateway to version 7.4.2 or later.
3
Who is affected by CVE-2014-6064?
CVE-2014-6064 affects users of McAfee Web Gateway versions prior to 7.3.2.9 and 7.4.x prior to 7.4.2.
4
What type of vulnerability is CVE-2014-6064?
CVE-2014-6064 is a security vulnerability that allows remote authenticated users to access hashed passwords.
5
When was CVE-2014-6064 published?
CVE-2014-6064 was published in October 2014.