Email Integrity Vulnerability in Enterprise Protection by Proofpoint
CVE-2025-0431

5.8MEDIUM

Key Information:

Vendor

Proofpoint

Vendor
CVE Published:
19 March 2025

What is CVE-2025-0431?

A vulnerability in URL rewriting within Proofpoint's Enterprise Protection can be exploited by unauthenticated remote attackers. This flaw allows attackers to send emails that bypass established URL protections, compromising the integrity of the recipient's email. The issue is attributed to the improper filtering of backslashes within URLs and affects all versions up to and including 8.21, 8.20, and 8.18 prior to their respective patches being applied.

Affected Version(s)

Enterprise Protection 8.18.6

Enterprise Protection 8.18.6

Enterprise Protection 8.20.6

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-0431 : Email Integrity Vulnerability in Enterprise Protection by Proofpoint