{"api_version":"1","generated_at":"2026-04-23T02:36:32+00:00","cve":"CVE-2021-23885","urls":{"html":"https://cve.report/CVE-2021-23885","api":"https://cve.report/api/cve/CVE-2021-23885.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-23885","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-23885"},"summary":{"title":"CVE-2021-23885","description":"Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain elevated privileges through the User Interface and execute commands on the appliance via incorrect improper neutralization of user input in the troubleshooting page.","state":"PUBLIC","assigner":"psirt@mcafee.com","published_at":"2021-02-17 10:15:00","updated_at":"2023-11-07 03:30:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10349","name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10349","refsource":"","tags":[],"title":"McAfee Security Bulletin - Web Gateway update fixes a Privilege escalation vulnerability (CVE-2021-23885)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-23885","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23885","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"23885","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"web_gateway","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"23885","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"web_gateway","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-23885","qid":"730227","title":"McAfee Web Gateway Multiple Vulnerabilities (WP-3426, WP-3427, WP-3307, WP-3444, WP-3452, WP-3475)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@mcafee.com","ID":"CVE-2021-23885","STATE":"PUBLIC","TITLE":"Privilege escalation vulnerability in McAfee Web Gateway (MWG) UI"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"McAfee Web Gateway (MWG)","version":{"version_data":[{"version_affected":"<","version_value":"9.2.8"}]}}]},"vendor_name":"McAfee,LLC"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain elevated privileges through the User Interface and execute commands on the appliance via incorrect improper neutralization of user input in the troubleshooting page."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-269: Improper Privilege Management "}]}]},"references":{"reference_data":[{"name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10349","refsource":"CONFIRM","url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10349"}]},"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2021-02-17 10:15:00","lastModifiedDate":"2023-11-07 03:30:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9},"severity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"10.0.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"9.2","versionEndExcluding":"9.2.8","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*","versionEndExcluding":"8.2.17","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"23885","Ordinal":"198625","Title":"CVE-2021-23885","CVE":"CVE-2021-23885","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"23885","Ordinal":"1","NoteData":"Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain elevated privileges through the User Interface and execute commands on the appliance via incorrect improper neutralization of user input in the troubleshooting page.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"23885","Ordinal":"2","NoteData":"2021-02-17","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"23885","Ordinal":"3","NoteData":"2021-02-17","Type":"Other","Title":"Modified"}]}}}