ID

VAR-202009-1309


CVE

CVE-2020-7297


TITLE

McAfee Web Gateway  Authentication vulnerabilities in

Trust: 0.8

sources: JVNDB: JVNDB-2020-011320

DESCRIPTION

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected dashboard data via improper access control in the user interface. McAfee Web Gateway (MWG) Contains an authentication vulnerability.Information may be obtained

Trust: 1.8

sources: NVD: CVE-2020-7297 // JVNDB: JVNDB-2020-011320 // VULHUB: VHN-185422 // VULMON: CVE-2020-7297

AFFECTED PRODUCTS

vendor:mcafeemodel:web gatewayscope:ltversion:9.2.1

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:8.2.0

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:ltversion:7.8.2.22

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:9.0.0

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:ltversion:8.2.9

Trust: 1.0

vendor:mcafeemodel:web gatewayscope:gteversion:7.8.0

Trust: 1.0

vendor:マカフィーmodel:mcafee web gateway ソフトウェアscope:eqversion: -

Trust: 0.8

vendor:マカフィーmodel:mcafee web gateway ソフトウェアscope:ltversion:mcafee web gateway software 9.2.1 less than

Trust: 0.8

sources: JVNDB: JVNDB-2020-011320 // NVD: CVE-2020-7297

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-7297
value: MEDIUM

Trust: 1.0

trellixpsirt@trellix.com: CVE-2020-7297
value: MEDIUM

Trust: 1.0

NVD: CVE-2020-7297
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202009-948
value: MEDIUM

Trust: 0.6

VULHUB: VHN-185422
value: LOW

Trust: 0.1

VULMON: CVE-2020-7297
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2020-7297
severity: LOW
baseScore: 2.7
vectorString: AV:A/AC:L/AU:S/C:P/I:N/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 5.1
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-185422
severity: LOW
baseScore: 2.7
vectorString: AV:A/AC:L/AU:S/C:P/I:N/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 5.1
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-7297
baseSeverity: MEDIUM
baseScore: 5.7
vectorString: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.1
impactScore: 3.6
version: 3.1

Trust: 2.0

OTHER: JVNDB-2020-011320
baseSeverity: MEDIUM
baseScore: 5.7
vectorString: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-185422 // VULMON: CVE-2020-7297 // JVNDB: JVNDB-2020-011320 // CNNVD: CNNVD-202009-948 // NVD: CVE-2020-7297 // NVD: CVE-2020-7297

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.1

problemtype:Improper authentication (CWE-287) [NVD Evaluation ]

Trust: 0.8

sources: VULHUB: VHN-185422 // JVNDB: JVNDB-2020-011320 // NVD: CVE-2020-7297

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202009-948

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202009-948

PATCH

title:SB10323url:https://kc.mcafee.com/corporate/index?page=content&id=SB10323

Trust: 0.8

title:McAfee Web Gateway Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=131064

Trust: 0.6

sources: JVNDB: JVNDB-2020-011320 // CNNVD: CNNVD-202009-948

EXTERNAL IDS

db:NVDid:CVE-2020-7297

Trust: 2.6

db:MCAFEEid:SB10323

Trust: 1.8

db:JVNDBid:JVNDB-2020-011320

Trust: 0.8

db:NSFOCUSid:50038

Trust: 0.6

db:CNNVDid:CNNVD-202009-948

Trust: 0.6

db:VULHUBid:VHN-185422

Trust: 0.1

db:VULMONid:CVE-2020-7297

Trust: 0.1

sources: VULHUB: VHN-185422 // VULMON: CVE-2020-7297 // JVNDB: JVNDB-2020-011320 // CNNVD: CNNVD-202009-948 // NVD: CVE-2020-7297

REFERENCES

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10323

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-7297

Trust: 1.4

url:http://www.nsfocus.net/vulndb/50038

Trust: 0.6

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10323

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/287.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-185422 // VULMON: CVE-2020-7297 // JVNDB: JVNDB-2020-011320 // CNNVD: CNNVD-202009-948 // NVD: CVE-2020-7297

SOURCES

db:VULHUBid:VHN-185422
db:VULMONid:CVE-2020-7297
db:JVNDBid:JVNDB-2020-011320
db:CNNVDid:CNNVD-202009-948
db:NVDid:CVE-2020-7297

LAST UPDATE DATE

2024-11-23T22:05:26.262000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-185422date:2022-07-01T00:00:00
db:VULMONid:CVE-2020-7297date:2022-07-01T00:00:00
db:JVNDBid:JVNDB-2020-011320date:2021-03-26T07:17:00
db:CNNVDid:CNNVD-202009-948date:2020-10-30T00:00:00
db:NVDid:CVE-2020-7297date:2024-11-21T05:37:00.803

SOURCES RELEASE DATE

db:VULHUBid:VHN-185422date:2020-09-16T00:00:00
db:VULMONid:CVE-2020-7297date:2020-09-16T00:00:00
db:JVNDBid:JVNDB-2020-011320date:2021-03-26T00:00:00
db:CNNVDid:CNNVD-202009-948date:2020-09-15T00:00:00
db:NVDid:CVE-2020-7297date:2020-09-16T00:15:12.303