CVE-2021-23884 describes a Cleartext Transmission of Sensitive Information vulnerability in McAfee Content Security Reporter (CSR) prior to version 2.8.0. This flaw allows an ePO administrator to view unencrypted passwords for McAfee Web Gateway (MWG) or MWG Cloud Server read-only users, which are used to retrieve log files for analysis within CSR. Rated 4.3 MEDIUM, the vulnerability requires high privileges and user interaction, with an adjacent network attack vector, potentially leading to high confidentiality impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.8.0CPE matchmatch criteria | cpe:2.3:a:mcafee:content_security_reporter:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.