Improper Certificate Validation in Proofpoint Insider Threat Management Agents for MacOS and Linux
CVE-2021-27899
7.4HIGH
Summary
The Proofpoint Insider Threat Management Agents for MacOS and Linux contain a vulnerability due to improper validation of the ITM Server's certificate. This flaw potentially allows a remote attacker to perform a man-in-the-middle attack, enabling them to intercept and manipulate communications between the agents and the server. It is crucial for users on affected versions to upgrade to version 7.11.1 or later to mitigate this risk. Agents for Windows and Cloud are unaffected.
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved