Email Gateway

Vendor:

First CVE: Apr 30, 2009 · Active for 17 years

20
Total CVEs
More Total CVEs than 95% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Email Gateway over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 30, 2009
17 years ago
Most Recent CVE
Sep 16, 2020
2,140 days ago

CVE Severity & Scoring

Email Gateway20 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (15.0%)
Unknown17 (85.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (15.0%)
High0 (0.0%)
Unknown17 (85.0%)
User Interaction
None2 (10.0%)
Unknown17 (85.0%)
Required1 (5.0%)
Privileges Required
Low2 (10.0%)
High0 (0.0%)
None1 (5.0%)
Unknown17 (85.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) Command or (2) Script XML eleme
Dec 14, 20139.028NONO
McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the value attribute in a (1) TestFile XML element or t
Dec 14, 20139.028NONO
McAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
Nov 2, 20138.526NONO
McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to bypass authentication an
Aug 22, 20127.523NONO
File extension filtering vulnerability in Intel Security McAfee Email Gateway (MEG) before 7.6.404h1128596 allows attackers to fail to identify the file name properly via scanning
Mar 14, 20176.522NONO
Cross-site scripting (XSS) vulnerability in McAfee Email Gateway (MEG) 7.6.x before 7.6.404, when File Filtering is enabled with the action set to ESERVICES:REPLACE, allows remote
Apr 6, 20166.122NONO
Multiple SQL injection vulnerabilities in /admin/cgi-bin/rpc/doReport/18 in McAfee Email Gateway 7.6 allow remote authenticated users to execute arbitrary SQL commands via the (1)
Dec 13, 20136.522NONO
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disable the server-side session token
Aug 22, 20126.821NONO
The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privileges to modify configuration v
May 28, 20106.521NONO
The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Ema
Apr 30, 20097.620NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Email Gateway

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.6.416.11.0%00
7.6.324.81.0%00
7.6.224.81.0%00
7.6.124.81.0%00
7.656.82.5%00
7.5.513.51.1%00
7.5.413.51.1%00
7.5.313.51.1%00
7.5.213.51.1%00
7.5.113.51.1%00
7.526.01.8%00
7.0.513.51.1%00
7.0.413.51.1%00
7.0.326.01.8%00
7.0.226.01.8%00
7.0.155.62.0%00
7.0.035.42.1%00
7.084.31.0%00
6.7.116.52.3%00