Proofpoint Enterprise Protection Endpoint Vulnerable to Improper Input Validation Attacks
CVE-2024-3676

7.5HIGH

Key Information:

Vendor
Proofpoint
Status
Enterprise Protection
Vendor
CVE Published:
14 May 2024

Summary

The Proofpoint Encryption component of Proofpoint Enterprise Protection is vulnerable due to improper input validation. This flaw enables unauthenticated remote attackers to exploit the system via specially crafted HTTP requests, potentially allowing the creation of additional encryption user accounts that are under their control. These malicious accounts can send spoofed emails to users within any configured domains, posing significant risks to organizations and compromising the integrity of email communications.

Affected Version(s)

Enterprise Protection 8.18.6

Enterprise Protection 8.18.6

Enterprise Protection 8.20.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.