CVE-2022-0815
MEDIUMMcafee Webadvisor < 8.1.0.1895 - Exposure to Wrong Actor
Title source: ruleDescription
Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could lead to unexpected behaviors including; settings being changed, fingerprinting of the system leading to targeted scams, and not triggering the malicious software if McAfee software is detected.
Scores
CVSS v3
6.5
EPSS
0.0038
EPSS Percentile
59.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Classification
CWE
CWE-668
Status
published
Affected Products (1)
mcafee/webadvisor
< 8.1.0.1895
Timeline
Published
Mar 10, 2022
Tracked Since
Feb 18, 2026