CVE-2020-7293

CRITICAL

McAfee Web Gateway 7.8.0-7.8.2.23 - Authenticated Privilege Escalation via User Interface

Title source: llm
STIX 2.1

Description

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change the system's root password via improper access controls in the user interface.

References (1)

Core 1
Core References

Scores

CVSS v3 9.0
EPSS 0.0010
EPSS Percentile 26.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
mcafee/web_gateway 7.8.0 - 7.8.2.23
Published Sep 15, 2020
Tracked Since Feb 18, 2026