First published: Tue Sep 15 2020(Updated: )
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected log data via improper access controls in the user interface.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Web Gateway | >=7.8.0<7.8.2.23 | |
McAfee Web Gateway | >=8.2.0<8.2.11 | |
McAfee Web Gateway | >=9.0.0<9.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-7295.
The affected software is McAfee Web Gateway versions 7.8.0 to 7.8.2.23, 8.2.0 to 8.2.11, and 9.0.0 to 9.2.3.
The severity of CVE-2020-7295 is medium with a CVSS score of 4.6.
This vulnerability allows an authenticated user to delete or download protected log data via improper access controls in the user interface.
To fix this vulnerability, update McAfee Web Gateway to version 9.2.1 or newer.