Описание
A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of PPS through 8.9.22 and 8.14.2 respectively, allows attackers to bypass protection mechanisms (related to extensions, MIME types, virus detection, and journal entries for transmitted files) by sending malformed (not RFC compliant) multipart email.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.9.22 (включая)Версия до 8.14.2 (включая)
Одно из
cpe:2.3:a:proofpoint:enterprise_protection:*:*:*:*:lts:*:*:*
cpe:2.3:a:proofpoint:enterprise_protection:*:*:*:*:-:*:*:*
EPSS
Процентиль: 57%
0.00353
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 3 лет назад
A file-extension filtering vulnerability in ProofPoint Protection Server Email Firewall through 8.10 allows attackers to bypass protection mechanisms (related to extensions, MIME types, virus detection, and journal entries for transmitted files) by sending malformed (not RFC compliant) multipart email.
EPSS
Процентиль: 57%
0.00353
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
NVD-CWE-Other