CVE-2018-6667
10.0
CRITICAL · CVSS 3.0 · EPSS 3.5% (pctl 89)
In your normal cycle
Critical by CVSS (10), but no sign of active exploitation.
Description
Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attackers to execute arbitrary code via Java management extensions (JMX).
Scoring
| CVSS | 10.0 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 3.52% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-06-26 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| mcafee | mcafee web gateway |
References
→ the Explorer · watch your stack · NVD