CVE-2019-3643

HIGHCVSS 7.5/10EPSS 2.39%

Last modified

CVE-2019-3643 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially leading to a denial of service. This affects the scanning proxies.. EPSS estimates a 2.39% chance of exploitation in the next 30 days.

Description

McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially leading to a denial of service. This affects the scanning proxies.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
2.39%

81.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
McafeeActive Response1.0.0
McafeeActive Response1.1.0
McafeeActive Response2.0
McafeeActive Response2.0.1
McafeeActive Response2.1
McafeeActive Response2.2
McafeeActive Response2.3
McafeeActive Response2.4
McafeeAdvanced Threat Defense4.0
McafeeAdvanced Threat Defense4.2
McafeeAdvanced Threat Defense4.4
McafeeAdvanced Threat Defense4.6
McafeeEnterprise Security Manager10.2.0
McafeeEnterprise Security Manager10.3.4
McafeeEnterprise Security Manager10.4.0
McafeeEnterprise Security Manager11.0.0
McafeeEnterprise Security Manager11.1.0
McafeeEnterprise Security Manager11.1.1
McafeeEnterprise Security Manager11.1.2
McafeeEnterprise Security Manager11.1.3
McafeeEnterprise Security Manager11.2.0
McafeeWeb Gateway>= 7.7.2.0, < 7.7.2.24
McafeeWeb Gateway>= 7.8.2, < 7.8.2.13
McafeeWeb Gateway>= 8.0.0, < 8.2.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-3643?
McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially leading to a denial of service. This affects the scanning proxies.
How severe is CVE-2019-3643?
CVE-2019-3643 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 2.39% probability of exploitation in the next 30 days.
How do I fix CVE-2019-3643?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-3643?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST