ID

VAR-202009-1306


CVE

CVE-2020-7294


TITLE

McAfee Web Gateway  Authentication vulnerabilities in

Trust: 0.8

sources: JVNDB: JVNDB-2020-011316

DESCRIPTION

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected files via improper access controls in the REST interface. McAfee Web Gateway (MWG) Contains an authentication vulnerability.Information may be obtained and information may be tampered with

Trust: 1.71

sources: NVD: CVE-2020-7294 // JVNDB: JVNDB-2020-011316 // VULHUB: VHN-185419

AFFECTED PRODUCTS

vendor:mcafeemodel:web gatewayscope:ltversion:9.2.3

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:ltversion:7.8.2.23

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:8.2.0

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:ltversion:8.2.11

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:9.0.0

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:7.8.0

Trust: 1.0

vendor:マカフィーmodel:mcafee web gateway ソフトウェアscope:eqversion: -

Trust: 0.8

vendor:マカフィーmodel:mcafee web gateway ソフトウェアscope:ltversion:mcafee web gateway software 9.2.1 less than

Trust: 0.8

sources: JVNDB: JVNDB-2020-011316 // NVD: CVE-2020-7294

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-7294
value: MEDIUM

Trust: 1.0

trellixpsirt@trellix.com: CVE-2020-7294
value: MEDIUM

Trust: 1.0

NVD: CVE-2020-7294
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202009-943
value: MEDIUM

Trust: 0.6

VULHUB: VHN-185419
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-7294
severity: MEDIUM
baseScore: 4.1
vectorString: AV:A/AC:L/AU:S/C:P/I:P/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 5.1
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-185419
severity: MEDIUM
baseScore: 4.1
vectorString: AV:A/AC:L/AU:S/C:P/I:P/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 5.1
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-7294
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.1
impactScore: 2.5
version: 3.1

Trust: 2.0

OTHER: JVNDB-2020-011316
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-185419 // JVNDB: JVNDB-2020-011316 // CNNVD: CNNVD-202009-943 // NVD: CVE-2020-7294 // NVD: CVE-2020-7294

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.1

problemtype:Improper authentication (CWE-287) [NVD Evaluation ]

Trust: 0.8

sources: VULHUB: VHN-185419 // JVNDB: JVNDB-2020-011316 // NVD: CVE-2020-7294

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202009-943

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202009-943

PATCH

title:SB10323url:https://kc.mcafee.com/corporate/index?page=content&id=SB10323

Trust: 0.8

title:McAfee Web Gateway Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=131061

Trust: 0.6

sources: JVNDB: JVNDB-2020-011316 // CNNVD: CNNVD-202009-943

EXTERNAL IDS

db:NVDid:CVE-2020-7294

Trust: 2.5

db:MCAFEEid:SB10323

Trust: 1.7

db:JVNDBid:JVNDB-2020-011316

Trust: 0.8

db:NSFOCUSid:50037

Trust: 0.6

db:CNNVDid:CNNVD-202009-943

Trust: 0.6

db:VULHUBid:VHN-185419

Trust: 0.1

sources: VULHUB: VHN-185419 // JVNDB: JVNDB-2020-011316 // CNNVD: CNNVD-202009-943 // NVD: CVE-2020-7294

REFERENCES

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10323

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-7294

Trust: 1.4

url:http://www.nsfocus.net/vulndb/50037

Trust: 0.6

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10323

Trust: 0.1

sources: VULHUB: VHN-185419 // JVNDB: JVNDB-2020-011316 // CNNVD: CNNVD-202009-943 // NVD: CVE-2020-7294

SOURCES

db:VULHUBid:VHN-185419
db:JVNDBid:JVNDB-2020-011316
db:CNNVDid:CNNVD-202009-943
db:NVDid:CVE-2020-7294

LAST UPDATE DATE

2024-11-23T22:05:26.210000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-185419date:2022-01-01T00:00:00
db:JVNDBid:JVNDB-2020-011316date:2021-03-26T07:17:00
db:CNNVDid:CNNVD-202009-943date:2020-10-30T00:00:00
db:NVDid:CVE-2020-7294date:2024-11-21T05:37:00.450

SOURCES RELEASE DATE

db:VULHUBid:VHN-185419date:2020-09-15T00:00:00
db:JVNDBid:JVNDB-2020-011316date:2021-03-26T00:00:00
db:CNNVDid:CNNVD-202009-943date:2020-09-15T00:00:00
db:NVDid:CVE-2020-7294date:2020-09-15T23:15:12.517