QID 12304

Date Published: 2022-01-18

QID 12304: McAfee Web Gateway Product Multiple Vulnerabilities (WP-2326,WP-3443)

McAfee Web Gateway Anti-Malware Engine, part of McAfee Web Protection, is a powerful in-line technology designed to protect against contemporary threats delivered via HTTP and HTTPS channels, taking web exploit detection, zero-day, and targeted threat prevention to the next level.

Affected Versions:
McAfee Web Gateway Web Gateway 9.2.x to 9.2.1
McAfee Web Gateway Web Gateway 8.2.x to 8.2.17

QID Detection Logic(Unauthenticated):
This QID retrieves McAfee Web Gateway version and checks to see if it's vulnerable.

An unauthenticated attacker could exploit this vulnerability to execute arbitrary code on the system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Please refer to McAfee Security Bulletin WP-2326Mcafee Web Gateway for more details.
    Software Advisories
    Advisory ID Software Component Link
    web-gateway-8.2.x URL Logo docs.mcafee.com/bundle/web-gateway-8.2.x-release-notes/page/GUID-1BC5FFB5-89B2-4FB7-A56F-1CAD9F7BAEA1.html
    web-gateway-9.2.x URL Logo docs.mcafee.com/bundle/web-gateway-9.2.x-release-notes/page/GUID-AB6795AC-0887-4434-950B-3E9937597576.html