CVE-2020-7294

MEDIUM

McAfee Web Gateway 7.8.0-7.8.2.23 - Authenticated Privilege Escalation via REST Interface

Title source: llm
STIX 2.1

Description

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected files via improper access controls in the REST interface.

References (1)

Core 1
Core References

Scores

CVSS v3 4.6
EPSS 0.0006
EPSS Percentile 19.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-287
Status published
Products (1)
mcafee/web_gateway 7.8.0 - 7.8.2.23
Published Sep 15, 2020
Tracked Since Feb 18, 2026