QID 730227

Date Published: 2021-11-11

QID 730227: McAfee Web Gateway Multiple Vulnerabilities (WP-3426, WP-3427, WP-3307, WP-3444, WP-3452, WP-3475)

McAfee Web Gateway delivers comprehensive security for all aspects of web traffic in one high-performance appliance software architecture.
For user-initiated web requests, McAfee Web Gateway first enforces an organization's internet use policy.

Affected Versions:
McAfee Web Gateway (MWG) 9.2.x prior to 9.2.8
McAfee Web Gateway (MWG) 8.2.x prior to 8.2.17

QID Detection Logic :
This QID retrieves McAfee Web Gateway version and checks to see if it's vulnerable.

Successful exploitation of these vulnerabilities affects the Confidentiality, Integrity, and Availability.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    McAfee MWG 8.2.17 and 9.2.8 updates releases address these vulnerabilities. Please visit McAfee Web Gateway Update 8.2.17 and McAfee Web Gateway Update 9.2.8 for fixes pertaining these vulnerabilities.
    Software Advisories
    Advisory ID Software Component Link
    McAfee Web Gateway Update 8.2.17 URL Logo docs.mcafee.com/bundle/web-gateway-8.2.x-release-notes/page/GUID-EDDF5551-2844-47B7-8A41-494AB15A9B00.html
    McAfee Web Gateway Update 9.2.8 URL Logo docs.mcafee.com/bundle/web-gateway-9.2.x-release-notes/page/GUID-BB83B2B1-19EE-4B7A-9F27-F5322D86BE38.html