ID

VAR-202009-1307


CVE

CVE-2020-7295


TITLE

McAfee Web Gateway  Authentication vulnerabilities in

Trust: 0.8

sources: JVNDB: JVNDB-2020-011317

DESCRIPTION

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected log data via improper access controls in the user interface. McAfee Web Gateway (MWG) Contains an authentication vulnerability.Information may be obtained and information may be tampered with

Trust: 1.8

sources: NVD: CVE-2020-7295 // JVNDB: JVNDB-2020-011317 // VULHUB: VHN-185420 // VULMON: CVE-2020-7295

AFFECTED PRODUCTS

vendor:mcafeemodel:web gatewayscope:ltversion:9.2.3

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:ltversion:7.8.2.23

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:8.2.0

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:ltversion:8.2.11

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:9.0.0

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:7.8.0

Trust: 1.0

vendor:マカフィーmodel:mcafee web gateway ソフトウェアscope:eqversion: -

Trust: 0.8

vendor:マカフィーmodel:mcafee web gateway ソフトウェアscope:ltversion:mcafee web gateway software 9.2.1 less than

Trust: 0.8

sources: JVNDB: JVNDB-2020-011317 // NVD: CVE-2020-7295

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-7295
value: MEDIUM

Trust: 1.0

trellixpsirt@trellix.com: CVE-2020-7295
value: LOW

Trust: 1.0

NVD: CVE-2020-7295
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202009-944
value: MEDIUM

Trust: 0.6

VULHUB: VHN-185420
value: MEDIUM

Trust: 0.1

VULMON: CVE-2020-7295
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-7295
severity: MEDIUM
baseScore: 4.1
vectorString: AV:A/AC:L/AU:S/C:P/I:P/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 5.1
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-185420
severity: MEDIUM
baseScore: 4.1
vectorString: AV:A/AC:L/AU:S/C:P/I:P/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 5.1
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-7295
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.1
impactScore: 2.5
version: 3.1

Trust: 1.0

trellixpsirt@trellix.com: CVE-2020-7295
baseSeverity: LOW
baseScore: 3.5
vectorString: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.1
impactScore: 1.4
version: 3.1

Trust: 1.0

NVD: CVE-2020-7295
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-185420 // VULMON: CVE-2020-7295 // JVNDB: JVNDB-2020-011317 // CNNVD: CNNVD-202009-944 // NVD: CVE-2020-7295 // NVD: CVE-2020-7295

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.1

problemtype:Improper authentication (CWE-287) [NVD Evaluation ]

Trust: 0.8

sources: VULHUB: VHN-185420 // JVNDB: JVNDB-2020-011317 // NVD: CVE-2020-7295

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202009-944

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202009-944

PATCH

title:SB10323url:https://kc.mcafee.com/corporate/index?page=content&id=SB10323

Trust: 0.8

title:McAfee Web Gateway Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=131062

Trust: 0.6

sources: JVNDB: JVNDB-2020-011317 // CNNVD: CNNVD-202009-944

EXTERNAL IDS

db:NVDid:CVE-2020-7295

Trust: 2.6

db:MCAFEEid:SB10323

Trust: 1.8

db:JVNDBid:JVNDB-2020-011317

Trust: 0.8

db:NSFOCUSid:50041

Trust: 0.6

db:CNNVDid:CNNVD-202009-944

Trust: 0.6

db:VULHUBid:VHN-185420

Trust: 0.1

db:VULMONid:CVE-2020-7295

Trust: 0.1

sources: VULHUB: VHN-185420 // VULMON: CVE-2020-7295 // JVNDB: JVNDB-2020-011317 // CNNVD: CNNVD-202009-944 // NVD: CVE-2020-7295

REFERENCES

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10323

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-7295

Trust: 1.4

url:http://www.nsfocus.net/vulndb/50041

Trust: 0.6

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10323

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/287.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-185420 // VULMON: CVE-2020-7295 // JVNDB: JVNDB-2020-011317 // CNNVD: CNNVD-202009-944 // NVD: CVE-2020-7295

SOURCES

db:VULHUBid:VHN-185420
db:VULMONid:CVE-2020-7295
db:JVNDBid:JVNDB-2020-011317
db:CNNVDid:CNNVD-202009-944
db:NVDid:CVE-2020-7295

LAST UPDATE DATE

2024-11-23T22:05:26.588000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-185420date:2022-01-06T00:00:00
db:VULMONid:CVE-2020-7295date:2020-10-19T00:00:00
db:JVNDBid:JVNDB-2020-011317date:2021-03-26T07:17:00
db:CNNVDid:CNNVD-202009-944date:2020-10-30T00:00:00
db:NVDid:CVE-2020-7295date:2024-11-21T05:37:00.560

SOURCES RELEASE DATE

db:VULHUBid:VHN-185420date:2020-09-15T00:00:00
db:VULMONid:CVE-2020-7295date:2020-09-15T00:00:00
db:JVNDBid:JVNDB-2020-011317date:2021-03-26T00:00:00
db:CNNVDid:CNNVD-202009-944date:2020-09-15T00:00:00
db:NVDid:CVE-2020-7295date:2020-09-15T23:15:12.597