CVE-2022-0815

MEDIUM

Mcafee Webadvisor < 8.1.0.1895 - Exposure to Wrong Actor

Title source: rule

Description

Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could lead to unexpected behaviors including; settings being changed, fingerprinting of the system leading to targeted scams, and not triggering the malicious software if McAfee software is detected.

Scores

CVSS v3 6.5
EPSS 0.0038
EPSS Percentile 59.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Classification

CWE
CWE-668
Status published

Affected Products (1)

mcafee/webadvisor < 8.1.0.1895

Timeline

Published Mar 10, 2022
Tracked Since Feb 18, 2026