Password Management Vulnerability in Skyhigh Secure Web Gateway by McAfee
CVE-2023-4400
What is CVE-2023-4400?
A vulnerability has been identified in the Skyhigh Secure Web Gateway (SWG) that allows sensitive authentication information to be compromised. This issue arises from the storage of passwords in plaintext within certain configuration files. As a result, an attacker leveraging the SWG REST API may access these credentials, posing significant security risks to affected installations. Organizations using affected versions should take immediate steps to remediate this vulnerability to safeguard their data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Skyhigh Secure Web Gateway (SWG) 11.x < 11.2.14
Skyhigh Secure Web Gateway (SWG) 10.x < 10.2.25
Skyhigh Secure Web Gateway (SWG) 12.x < 12.2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
