CVE Database
/

CVE-2021-23884

Back to search

CVE-2021-23884

Published: Apr 15, 2021

Modified: Aug 3, 2024

PUBLISHED

CVSS v3.1

4.3

MEDIUM

Description

Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee Content Security Reporter (CSR) prior to 2.8.0 allows an ePO administrator to view the unencrypted password of the McAfee Web Gateway (MWG) or the password of the McAfee Web Gateway Cloud Server (MWGCS) read only user used to retrieve log files for analysis in CSR.

VendorProductVersions

McAfee,LLC

McAfee Content Security Reporter (CSR)

affected
unspecified - < 2.8.0CWE-319: Cleartext Transmission of Sensitive Information

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

High

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2021-23884 | MEDIUM (4.3) - Security Vulnerability | QwikSec