CVE-2020-7292: Web Gateway (MWG) - Inappropriate Encoding for output context
Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attacker to cause MWG to return an ambiguous redirect response via getting a user to click on a malicious URL.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7292?
CVE-2020-7292 is a vulnerability in McAfee Web Gateway (MWG) prior to version 9.2.1 that allows a remote attacker to cause MWG to return an ambiguous redirect response via getting a user to click on a malicious URL.
What is the severity of CVE-2020-7292?
CVE-2020-7292 has a severity rating of 4.3 (medium).
How does CVE-2020-7292 affect McAfee Web Gateway?
CVE-2020-7292 affects McAfee Web Gateway versions prior to 9.2.1.
How can a remote attacker exploit CVE-2020-7292?
A remote attacker can exploit CVE-2020-7292 by getting a user to click on a malicious URL, causing MWG to return an ambiguous redirect response.
Is there a fix for CVE-2020-7292?
Yes, updating McAfee Web Gateway to version 9.2.1 or later resolves the CVE-2020-7292 vulnerability.