Search
Find a vulnerability
Search criteria
2 vulnerabilities by prootpoint
CVE-2024-3676 (GCVE-0-2024-3676)
Vulnerability from nvd – Published: 2024-05-14 19:07 – Updated: 2024-08-01 20:19
VLAI
EPSS
VEX
Summary
The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's control. These accounts are able to send spoofed email to any users within the domains configured by the Administrator.
Severity
7.5 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-05-15 17:49 UTC
CWE
- CWE-20 - Improper Input Validation
Assigner
References
1 reference
Impacted products
6 products
| Vendor | Product | Version | |
|---|---|---|---|
| Proofpoint | Enterprise Protection |
Affected:
8.18.6 , < patch 4868
(semver)
Affected: 8.20.0 , < patch 4869 (semver) Affected: 8.20.2 , < patch 4870 (semver) Affected: 8.20.4 , < patch 4871 (semver) Affected: 8.21.0 , < patch 4871 (semver) |
|
| proofpoint | enterprise_protection |
Affected:
8.18.6 , < patch_4868
(custom)
cpe:2.3:a:proofpoint:enterprise_protection:8.18.6:*:*:*:*:*:*:* |
|
| proofpoint | enterprise_protection |
Affected:
8.20.0 , < patch_4869
(custom)
cpe:2.3:a:proofpoint:enterprise_protection:8.20.0:-:*:*:*:*:*:* |
|
| proofpoint | enterprise_protection |
Affected:
8.20.2 , < patch_4870
(custom)
cpe:2.3:a:proofpoint:enterprise_protection:8.20.2:*:*:*:*:*:*:* |
|
| prootpoint | enterprise_protection |
Affected:
8.20.4 , < patch_4871
(custom)
cpe:2.3:a:prootpoint:enterprise_protection:8.20.4:*:*:*:*:*:*:* |
|
| prootpoint | enterprise_protection |
Affected:
8.21.0 , < patch_4872
(custom)
cpe:2.3:a:prootpoint:enterprise_protection:8.21.0:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:proofpoint:enterprise_protection:8.18.6:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "enterprise_protection",
"vendor": "proofpoint",
"versions": [
{
"lessThan": "patch_4868",
"status": "affected",
"version": "8.18.6",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:a:proofpoint:enterprise_protection:8.20.0:-:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "enterprise_protection",
"vendor": "proofpoint",
"versions": [
{
"lessThan": "patch_4869 ",
"status": "affected",
"version": "8.20.0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:a:proofpoint:enterprise_protection:8.20.2:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "enterprise_protection",
"vendor": "proofpoint",
"versions": [
{
"lessThan": "patch_4870",
"status": "affected",
"version": "8.20.2",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:a:prootpoint:enterprise_protection:8.20.4:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "enterprise_protection",
"vendor": "prootpoint",
"versions": [
{
"lessThan": "patch_4871",
"status": "affected",
"version": "8.20.4",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:a:prootpoint:enterprise_protection:8.21.0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "enterprise_protection",
"vendor": "prootpoint",
"versions": [
{
"lessThan": "patch_4872",
"status": "affected",
"version": "8.21.0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-3676",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-05-15T17:49:37.326859Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-04T17:31:16.298Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T20:19:59.948Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2024-0002"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "Enterprise Protection",
"vendor": "Proofpoint",
"versions": [
{
"changes": [
{
"at": "patch 4868",
"status": "unaffected"
}
],
"lessThan": "patch 4868",
"status": "affected",
"version": "8.18.6",
"versionType": "semver"
},
{
"changes": [
{
"at": "patch 4869",
"status": "unaffected"
}
],
"lessThan": "patch 4869",
"status": "affected",
"version": "8.20.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "patch 4870",
"status": "unaffected"
}
],
"lessThan": "patch 4870",
"status": "affected",
"version": "8.20.2",
"versionType": "semver"
},
{
"changes": [
{
"at": "patch 4871",
"status": "unaffected"
}
],
"lessThan": "patch 4871",
"status": "affected",
"version": "8.20.4",
"versionType": "semver"
},
{
"changes": [
{
"at": "patch 4872",
"status": "unaffected"
}
],
"lessThan": "patch 4871",
"status": "affected",
"version": "8.21.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker\u0027s control.\u0026nbsp; These accounts are able to send spoofed email to any users within the domains configured by the Administrator."
}
],
"value": "The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker\u0027s control.\u00a0 These accounts are able to send spoofed email to any users within the domains configured by the Administrator."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-05-14T19:07:19.420Z",
"orgId": "d83a79dd-e128-4b83-8b64-84faf54eed46",
"shortName": "Proofpoint"
},
"references": [
{
"url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2024-0002"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "d83a79dd-e128-4b83-8b64-84faf54eed46",
"assignerShortName": "Proofpoint",
"cveId": "CVE-2024-3676",
"datePublished": "2024-05-14T19:07:19.420Z",
"dateReserved": "2024-04-11T20:00:59.260Z",
"dateUpdated": "2024-08-01T20:19:59.948Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-3676 (GCVE-0-2024-3676)
Vulnerability from cvelistv5 – Published: 2024-05-14 19:07 – Updated: 2024-08-01 20:19
VLAI
EPSS
VEX
Summary
The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's control. These accounts are able to send spoofed email to any users within the domains configured by the Administrator.
Severity
7.5 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-05-15 17:49 UTC
CWE
- CWE-20 - Improper Input Validation
Assigner
References
1 reference
Impacted products
6 products
| Vendor | Product | Version | |
|---|---|---|---|
| Proofpoint | Enterprise Protection |
Affected:
8.18.6 , < patch 4868
(semver)
Affected: 8.20.0 , < patch 4869 (semver) Affected: 8.20.2 , < patch 4870 (semver) Affected: 8.20.4 , < patch 4871 (semver) Affected: 8.21.0 , < patch 4871 (semver) |
|
| proofpoint | enterprise_protection |
Affected:
8.18.6 , < patch_4868
(custom)
cpe:2.3:a:proofpoint:enterprise_protection:8.18.6:*:*:*:*:*:*:* |
|
| proofpoint | enterprise_protection |
Affected:
8.20.0 , < patch_4869
(custom)
cpe:2.3:a:proofpoint:enterprise_protection:8.20.0:-:*:*:*:*:*:* |
|
| proofpoint | enterprise_protection |
Affected:
8.20.2 , < patch_4870
(custom)
cpe:2.3:a:proofpoint:enterprise_protection:8.20.2:*:*:*:*:*:*:* |
|
| prootpoint | enterprise_protection |
Affected:
8.20.4 , < patch_4871
(custom)
cpe:2.3:a:prootpoint:enterprise_protection:8.20.4:*:*:*:*:*:*:* |
|
| prootpoint | enterprise_protection |
Affected:
8.21.0 , < patch_4872
(custom)
cpe:2.3:a:prootpoint:enterprise_protection:8.21.0:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:proofpoint:enterprise_protection:8.18.6:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "enterprise_protection",
"vendor": "proofpoint",
"versions": [
{
"lessThan": "patch_4868",
"status": "affected",
"version": "8.18.6",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:a:proofpoint:enterprise_protection:8.20.0:-:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "enterprise_protection",
"vendor": "proofpoint",
"versions": [
{
"lessThan": "patch_4869 ",
"status": "affected",
"version": "8.20.0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:a:proofpoint:enterprise_protection:8.20.2:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "enterprise_protection",
"vendor": "proofpoint",
"versions": [
{
"lessThan": "patch_4870",
"status": "affected",
"version": "8.20.2",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:a:prootpoint:enterprise_protection:8.20.4:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "enterprise_protection",
"vendor": "prootpoint",
"versions": [
{
"lessThan": "patch_4871",
"status": "affected",
"version": "8.20.4",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:a:prootpoint:enterprise_protection:8.21.0:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "enterprise_protection",
"vendor": "prootpoint",
"versions": [
{
"lessThan": "patch_4872",
"status": "affected",
"version": "8.21.0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-3676",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-05-15T17:49:37.326859Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-04T17:31:16.298Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T20:19:59.948Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2024-0002"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "Enterprise Protection",
"vendor": "Proofpoint",
"versions": [
{
"changes": [
{
"at": "patch 4868",
"status": "unaffected"
}
],
"lessThan": "patch 4868",
"status": "affected",
"version": "8.18.6",
"versionType": "semver"
},
{
"changes": [
{
"at": "patch 4869",
"status": "unaffected"
}
],
"lessThan": "patch 4869",
"status": "affected",
"version": "8.20.0",
"versionType": "semver"
},
{
"changes": [
{
"at": "patch 4870",
"status": "unaffected"
}
],
"lessThan": "patch 4870",
"status": "affected",
"version": "8.20.2",
"versionType": "semver"
},
{
"changes": [
{
"at": "patch 4871",
"status": "unaffected"
}
],
"lessThan": "patch 4871",
"status": "affected",
"version": "8.20.4",
"versionType": "semver"
},
{
"changes": [
{
"at": "patch 4872",
"status": "unaffected"
}
],
"lessThan": "patch 4871",
"status": "affected",
"version": "8.21.0",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker\u0027s control.\u0026nbsp; These accounts are able to send spoofed email to any users within the domains configured by the Administrator."
}
],
"value": "The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker\u0027s control.\u00a0 These accounts are able to send spoofed email to any users within the domains configured by the Administrator."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20 Improper Input Validation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-05-14T19:07:19.420Z",
"orgId": "d83a79dd-e128-4b83-8b64-84faf54eed46",
"shortName": "Proofpoint"
},
"references": [
{
"url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2024-0002"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "d83a79dd-e128-4b83-8b64-84faf54eed46",
"assignerShortName": "Proofpoint",
"cveId": "CVE-2024-3676",
"datePublished": "2024-05-14T19:07:19.420Z",
"dateReserved": "2024-04-11T20:00:59.260Z",
"dateUpdated": "2024-08-01T20:19:59.948Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}