Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10657

Опубликовано: 06 янв. 2021
Источник: nvd
CVSS3: 7.2
CVSS2: 6.5
EPSS Низкий

Описание

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM web console's ImportAlertRules feature. The vulnerability allows a remote attacker (with admin or config-admin privileges in the console) to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:proofpoint:insider_threat_management_server:*:*:*:*:*:*:*:*
Версия до 7.9.1 (исключая)

EPSS

Процентиль: 89%
0.04585
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-502

Связанные уязвимости

github
больше 3 лет назад

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM web console's ImportAlertRules feature. The vulnerability allows a remote attacker (with admin or config-admin privileges in the console) to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.

EPSS

Процентиль: 89%
0.04585
Низкий

7.2 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-502