QID 730206

Date Published: 2021-09-22

QID 730206: McAfee Web Gateway Multiple Vulnerabilities (WP-3792, WP-4003, WP-4021, WP-4058, WP-4067)

McAfee Web Gateway delivers comprehensive security for all aspects of web traffic in one high-performance appliance software architecture.
For user-initiated web requests, McAfee Web Gateway first enforces an organization's internet use policy.

Release 8.2.23, 9.2.14 and 10.2.3 includes updates addressing publicly disclosed CVEs, regardless of whether a CVE has been shown to impact customers. Affected Versions:
McAfee Web Gateway (MWG) 10.2.x prior to 10.2.3
McAfee Web Gateway (MWG) 9.2.x prior to 9.2.14
McAfee Web Gateway (MWG) 8.2.x prior to 8.2.23

QID Detection Logic :
This QID retrieves McAfee Web Gateway version and checks to see if it's vulnerable.

Successful exploitation of these vulnerabilities affects the Confidentiality, Integrity and Availability

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    McAfee MWG 8.2.24, 9.2.14 and 10.2.3 update releases address these vulnerabilities. Please visit McAfee Web Gateway Update 8.2.23, McAfee Web Gateway Update 9.2.14 and McAfee Web Gateway Update 10.2.3for more details.

    Software Advisories
    Advisory ID Software Component Link
    McAfee Web Gateway Update 10.2.3 URL Logo docs.mcafee.com/bundle/web-gateway-10.2.x-release-notes/page/GUID-1C3CF898-019F-491B-B60D-26C610D730D4.html
    McAfee Web Gateway Update 8.2.23 URL Logo docs.mcafee.com/bundle/web-gateway-8.2.x-release-notes/page/GUID-B452B6F5-448C-4C7C-A72B-4FBEA86C0475.html
    McAfee Web Gateway Update 9.2.14 URL Logo docs.mcafee.com/bundle/web-gateway-9.2.x-release-notes/page/GUID-92EA516F-69C8-4870-B1FF-E956E06D3330.html