Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configuration files to be extracted through SWG REST API. This was possible due to SWG storing the password in plain text in some configuration files.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N
Vulnerability Type
明文存储口令
Vulnerability Title
McAfee Skyhigh Secure Web Gateway 安全漏洞
Vulnerability Description
McAfee Skyhigh Secure Web Gateway(McAfee Skyhigh SWG)是美国迈克菲(McAfee)公司的一系列安全网关。 McAfee Skyhigh Secure Web Gateway 存在安全漏洞,该漏洞源于存在密码管理漏洞,允许以纯文本形式存储密码。
CVSS Information
N/A
Vulnerability Type
N/A