CVE-2024-3676
Published: May 14, 2024
Modified: Aug 1, 2024
CVSS v3.1
7.5
Description
The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's control. These accounts are able to send spoofed email to any users within the domains configured by the Administrator.
| Vendor | Product | Versions |
|---|---|---|
Proofpoint | Enterprise Protection | affected 8.18.6 - < patch 4868affected 8.20.0 - < patch 4869affected 8.20.2 - < patch 4870affected 8.20.4 - < patch 4871affected 8.21.0 - < patch 4871 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now