CVE-2021-23885: Privilege escalation vulnerability in McAfee Web Gateway (MWG) UI
Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain elevated privileges through the User Interface and execute commands on the appliance via incorrect improper neutralization of user input in the troubleshooting page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23885?
CVE-2021-23885 is a privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to version 9.2.8.
How does CVE-2021-23885 allow an attacker to gain elevated privileges?
CVE-2021-23885 allows an authenticated user to gain elevated privileges through the User Interface and execute commands on the appliance via incorrect improper neutralization of user input in the troubleshooting page.
Which versions of McAfee Web Gateway are affected by CVE-2021-23885?
McAfee Web Gateway versions prior to 9.2.8 are affected by CVE-2021-23885.
What is the severity of CVE-2021-23885?
CVE-2021-23885 has a severity rating of 8.8 (Critical).
How can I fix CVE-2021-23885?
To fix CVE-2021-23885, users should update McAfee Web Gateway to version 9.2.8 or higher.