CVE-2021-23885

Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain elevated privileges through the User Interface and execute commands on the appliance via incorrect improper neutralization of user input in the troubleshooting page.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:30

Type Values Removed Values Added
References (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10349 - Vendor Advisory () https://kc.mcafee.com/corporate/index?page=content&id=SB10349 -

26 Apr 2022, 15:59

Type Values Removed Values Added
CWE CWE-269 NVD-CWE-Other

22 Feb 2021, 20:41

Type Values Removed Values Added
References (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10349 - (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10349 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 9.0
v3 : 8.8
CPE cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*

17 Feb 2021, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-02-17 10:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-23885

Mitre link : CVE-2021-23885

CVE.ORG link : CVE-2021-23885


JSON object : View

Products Affected

mcafee

  • web_gateway
CWE
NVD-CWE-Other CWE-269

Improper Privilege Management