Loading vulnerability details…
CVSS v3.1
4.3
EPSS
0.21%
Published
Apr 15, 2021
Modified
Nov 21, 2024
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee Content Security Reporter (CSR) prior to 2.8.0 allows an ePO administrator to view the unencrypted password of the McAfee Web Gateway (MWG) or the password of the McAfee Web Gateway Cloud Server (MWGCS) read only user used to retrieve log files for analysis in CSR.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:NWeaknesses (CWE)
Affected Products (1)
References (2)