QID 730228

Date Published: 2021-10-13

QID 730228: McAfee Web Gateway Multiple Vulnerabilities (WP-3445, WP-3483, WP-3527, WP-3528, WP-3547, WP-3584,WP-3589,WP-3611)

McAfee Web Gateway delivers comprehensive security for all aspects of web traffic in one high-performance appliance software architecture. For user-initiated web requests, McAfee Web Gateway first enforces an organization's internet use policy. Release 8.2.19 and 9.2.10 includes updates addressing publicly disclosed CVEs, regardless of whether a CVE has been shown to impact customers. Affected Versions:
McAfee Web Gateway (MWG) 9.2.x prior to 9.2.10
McAfee Web Gateway (MWG) 8.2.x prior to 8.2.19

QID Detection Logic :
This QID retrieves McAfee Web Gateway version and checks to see if it's vulnerable.

Successful exploitation of these vulnerabilities affects the Confidentiality, Integrity and Availability

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    McAfee MWG 8.2.19 and 9.2.10 update releases address these vulnerabilities. Please visit McAfee Web Gateway Update 8.2.19, McAfee Web Gateway Update 9.2.10 for more details.

    Software Advisories
    Advisory ID Software Component Link
    web-gateway-8.2.x URL Logo docs.mcafee.com/bundle/web-gateway-8.2.x-release-notes/page/GUID-8ABC8498-051E-4569-BE1E-40E7C306FAAF.html
    web-gateway-9.2.x URL Logo docs.mcafee.com/bundle/web-gateway-9.2.x-release-notes/page/GUID-F9F75E52-564D-445C-8645-D3A79947E16C.html