cvelist/2020/7xxx/CVE-2020-7294.json

88 lines
2.7 KiB
JSON
Raw Normal View History

2020-01-21 14:01:28 +00:00
{
"CVE_data_meta": {
2020-09-15 17:59:43 -05:00
"ASSIGNER": "psirt@mcafee.com",
2020-01-21 14:01:28 +00:00
"ID": "CVE-2020-7294",
2020-09-15 17:59:43 -05:00
"STATE": "PUBLIC",
"TITLE": "Web Gateway (MWG) - Privilege Escalation vulnerability"
2020-01-21 14:01:28 +00:00
},
2020-09-15 17:59:43 -05:00
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "McAfee Web Gateway (MWG)",
"version": {
"version_data": [
{
"version_affected": "<",
"version_value": "9.2.1"
}
]
}
}
]
},
"vendor_name": "McAfee"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
2020-01-21 14:01:28 +00:00
"description": {
"description_data": [
{
"lang": "eng",
2020-09-16 00:01:53 +00:00
"value": "Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected files via improper access controls in the REST interface."
2020-09-15 17:59:43 -05:00
}
]
},
"generator": {
"engine": "Vulnogram 0.0.9"
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.6,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
2020-10-19 10:21:48 +01:00
"value": "CWE-287: Improper Authentication"
2020-09-15 17:59:43 -05:00
}
]
2020-01-21 14:01:28 +00:00
}
]
2020-09-15 17:59:43 -05:00
},
"references": {
"reference_data": [
{
2020-09-16 00:01:53 +00:00
"refsource": "MISC",
"url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10323",
"name": "https://kc.mcafee.com/corporate/index?page=content&id=SB10323"
2020-09-15 17:59:43 -05:00
}
]
},
"source": {
"advisory": "SB10323",
"discovery": "EXTERNAL"
2020-01-21 14:01:28 +00:00
}
2020-10-19 10:21:48 +01:00
}