CVE-2018-6667: McAfee Web Gateway - Authentication Bypass vulnerability
Published Jun 26, 2018
·Updated
Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attackers to execute arbitrary code via Java management extensions (JMX).
Affected Software
1 affected component
McAfee McAfee Web Gateway>=7.8.1.0<=7.8.1.5
Event History
Jun 26, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6667?
CVE-2018-6667 is considered to have a high severity due to the potential for remote code execution.
2
How do I fix CVE-2018-6667?
To mitigate CVE-2018-6667, upgrade McAfee Web Gateway to version 7.8.1.6 or later.
3
Who is affected by CVE-2018-6667?
CVE-2018-6667 affects McAfee Web Gateway versions 7.8.1.0 through 7.8.1.5.
4
What does CVE-2018-6667 exploit?
CVE-2018-6667 exploits an authentication bypass vulnerability in the administrative user interface.
5
Can CVE-2018-6667 allow unauthorized access?
Yes, CVE-2018-6667 can allow remote attackers to gain unauthorized access and execute arbitrary code.