SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-2116

The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privileges to modify configuration via the save action in a direct request to admin/systemWebAdminConfig.do.

MEDIUM 6.5EPSS 2.31%

Does this matter?

Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.

Description

The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privileges to modify configuration via the save action in a direct request to admin/systemWebAdminConfig.do.

CVSS 2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
2.31% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-732
Affected
mcafee/email gateway · mcafee/secure mail
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.