Information Disclosure Vulnerability in Proofpoint Threat Response Services
CVE-2023-2820
6.8MEDIUM
What is CVE-2023-2820?
A vulnerability present in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) allows attackers on adjacent networks to exploit weaknesses in the faye endpoint. This could enable them to capture session traffic or perform cryptanalysis, potentially exposing credentials to integrated services. With these credentials, an attacker could impersonate PTR/TRAP and gain unauthorized access to sensitive services. Affected versions include all prior to 5.10.0.
Affected Version(s)
Threat Response Auto Pull 0 < 5.10.0