CVE-2020-7295

EUVD-2020-28422
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected log data via improper access controls in the user interface.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.5 LOW
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
trellixCNA
3.5 LOW
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
Affected Products (NVD)
VendorProductVersion
mcafeeweb_gateway
7.8.0 ≤
𝑥
< 7.8.2.23
mcafeeweb_gateway
8.2.0 ≤
𝑥
< 8.2.11
mcafeeweb_gateway
9.0.0 ≤
𝑥
< 9.2.3
𝑥
= Vulnerable software versions