McAfee Web Gateway User Interface Default Credentials

critical Nessus Plugin ID 72622

Synopsis

The remote web service is protected using a default set of known credentials.

Description

The remote McAfee Web Gateway user interface uses a known set of default credentials. Knowing these, an attacker with access to service can gain administrative access to the device.

Solution

Change the default admin login credentials.

Plugin Details

Severity: Critical

ID: 72622

File Name: mcafee_web_gateway_konfigurator_default_creds.nasl

Version: 1.4

Type: remote

Family: CGI abuses

Published: 2/21/2014

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/h:mcafee:web_gateway

Required KB Items: www/mwg_ui

Excluded KB Items: global_settings/supplied_logins_only