Input validation error in McAfee Web Gateway - CVE-2018-6678

 

Input validation error in McAfee Web Gateway - CVE-2018-6678

Published: July 23, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36827
CSH Severity: High
CVSS v4: 6.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2018-6678
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to execute arbitrary code.

Configuration/Environment manipulation vulnerability in the administrative interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows authenticated administrator users to execute arbitrary commands via unspecified vectors.


Affected software

McAfee Web Gateway

How to mitigate CVE-2018-6678

Install update from vendor's website.


External References

Related Security Bulletins