ID

VAR-202009-1308


CVE

CVE-2020-7296


TITLE

McAfee Web Gateway  Authentication vulnerabilities in

Trust: 0.8

sources: JVNDB: JVNDB-2020-011318

DESCRIPTION

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected configuration files via improper access control in the user interface. McAfee Web Gateway (MWG) Contains an authentication vulnerability.Information may be obtained

Trust: 1.71

sources: NVD: CVE-2020-7296 // JVNDB: JVNDB-2020-011318 // VULHUB: VHN-185421

AFFECTED PRODUCTS

vendor:mcafeemodel:web gatewayscope:ltversion:9.2.3

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:ltversion:7.8.2.23

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:8.2.0

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:ltversion:8.2.11

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:9.0.0

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:7.8.0

Trust: 1.0

vendor:マカフィーmodel:mcafee web gateway ソフトウェアscope:eqversion: -

Trust: 0.8

vendor:マカフィーmodel:mcafee web gateway ソフトウェアscope:ltversion:mcafee web gateway software 9.2.1 less than

Trust: 0.8

sources: JVNDB: JVNDB-2020-011318 // NVD: CVE-2020-7296

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-7296
value: MEDIUM

Trust: 1.0

trellixpsirt@trellix.com: CVE-2020-7296
value: MEDIUM

Trust: 1.0

NVD: CVE-2020-7296
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202009-947
value: MEDIUM

Trust: 0.6

VULHUB: VHN-185421
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2020-7296
severity: LOW
baseScore: 2.7
vectorString: AV:A/AC:L/AU:S/C:P/I:N/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 5.1
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-185421
severity: LOW
baseScore: 2.7
vectorString: AV:A/AC:L/AU:S/C:P/I:N/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 5.1
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-7296
baseSeverity: MEDIUM
baseScore: 5.7
vectorString: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.1
impactScore: 3.6
version: 3.1

Trust: 2.0

OTHER: JVNDB-2020-011318
baseSeverity: MEDIUM
baseScore: 5.7
vectorString: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-185421 // JVNDB: JVNDB-2020-011318 // CNNVD: CNNVD-202009-947 // NVD: CVE-2020-7296 // NVD: CVE-2020-7296

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.1

problemtype:Improper authentication (CWE-287) [NVD Evaluation ]

Trust: 0.8

sources: VULHUB: VHN-185421 // JVNDB: JVNDB-2020-011318 // NVD: CVE-2020-7296

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202009-947

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202009-947

PATCH

title:SB10323url:https://kc.mcafee.com/corporate/index?page=content&id=SB10323

Trust: 0.8

title:McAfee Web Gateway Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=131063

Trust: 0.6

sources: JVNDB: JVNDB-2020-011318 // CNNVD: CNNVD-202009-947

EXTERNAL IDS

db:NVDid:CVE-2020-7296

Trust: 2.5

db:MCAFEEid:SB10323

Trust: 1.7

db:JVNDBid:JVNDB-2020-011318

Trust: 0.8

db:NSFOCUSid:50040

Trust: 0.6

db:CNNVDid:CNNVD-202009-947

Trust: 0.6

db:VULHUBid:VHN-185421

Trust: 0.1

sources: VULHUB: VHN-185421 // JVNDB: JVNDB-2020-011318 // CNNVD: CNNVD-202009-947 // NVD: CVE-2020-7296

REFERENCES

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10323

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-7296

Trust: 1.4

url:http://www.nsfocus.net/vulndb/50040

Trust: 0.6

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10323

Trust: 0.1

sources: VULHUB: VHN-185421 // JVNDB: JVNDB-2020-011318 // CNNVD: CNNVD-202009-947 // NVD: CVE-2020-7296

SOURCES

db:VULHUBid:VHN-185421
db:JVNDBid:JVNDB-2020-011318
db:CNNVDid:CNNVD-202009-947
db:NVDid:CVE-2020-7296

LAST UPDATE DATE

2024-11-23T22:05:26.562000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-185421date:2022-01-06T00:00:00
db:JVNDBid:JVNDB-2020-011318date:2021-03-26T07:17:00
db:CNNVDid:CNNVD-202009-947date:2020-10-30T00:00:00
db:NVDid:CVE-2020-7296date:2024-11-21T05:37:00.670

SOURCES RELEASE DATE

db:VULHUBid:VHN-185421date:2020-09-15T00:00:00
db:JVNDBid:JVNDB-2020-011318date:2021-03-26T00:00:00
db:CNNVDid:CNNVD-202009-947date:2020-09-15T00:00:00
db:NVDid:CVE-2020-7296date:2020-09-15T23:15:12.673