VulnerabilityModified
CVE-2010-2116
The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privileges to modify configuration via the save action in a direct request to admin/systemWebAdminConfig.do.
MEDIUM 6.5EPSS 2.31%
Does this matter?
Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.
Description
The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privileges to modify configuration via the save action in a direct request to admin/systemWebAdminConfig.do.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 2.31% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- mcafee/email gateway · mcafee/secure mail
- Source
- cve@mitre.org
References
- http://osvdb.org/64832Broken Link
- http://secunia.com/advisories/39881Vendor Advisory
- http://www.cybsec.com/vuln/cybsec_advisory_2010_0501_Ironmail_Advisory_Web_Access_Broken.pdfExploit
- http://www.securitytracker.com/id?1024018Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/1239Vendor Advisory
- http://osvdb.org/64832Broken Link
- http://secunia.com/advisories/39881Vendor Advisory
- http://www.cybsec.com/vuln/cybsec_advisory_2010_0501_Ironmail_Advisory_Web_Access_Broken.pdfExploit
- http://www.securitytracker.com/id?1024018Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/1239Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.