Proofpoint Enterprise Protection Endpoint Vulnerable to Improper Input Validation Attacks
CVE-2024-3676
7.5HIGH
Key Information:
- Vendor
- Proofpoint
- Status
- Enterprise Protection
- Vendor
- CVE Published:
- 14 May 2024
Summary
The Proofpoint Encryption component of Proofpoint Enterprise Protection is vulnerable due to improper input validation. This flaw enables unauthenticated remote attackers to exploit the system via specially crafted HTTP requests, potentially allowing the creation of additional encryption user accounts that are under their control. These malicious accounts can send spoofed emails to users within any configured domains, posing significant risks to organizations and compromising the integrity of email communications.
Affected Version(s)
Enterprise Protection 8.18.6
Enterprise Protection 8.18.6
Enterprise Protection 8.20.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved