Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-2820

Опубликовано: 14 июн. 2023
Источник: nvd
CVSS3: 6.1
CVSS3: 6.8
EPSS Низкий

Описание

An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated services via a man-in-the-middle position or cryptanalysis of the session traffic. An attacker could use these credentials to impersonate PTR/TRAP to these services. All versions prior to 5.10.0 are affected. 

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:proofpoint:threat_response_auto_pull:*:*:*:*:*:*:*:*
Версия до 5.10.0 (исключая)

EPSS

Процентиль: 18%
0.00056
Низкий

6.1 Medium

CVSS3

6.8 Medium

CVSS3

Дефекты

CWE-200
CWE-668

Связанные уязвимости

CVSS3: 6.1
github
больше 2 лет назад

An information disclosure vulnerability in the?faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated services via a man-in-the-middle position or cryptanalysis of the session traffic. An attacker could use these credentials to impersonate PTR/TRAP to these services. All versions prior to 5.10.0 are affected. 

EPSS

Процентиль: 18%
0.00056
Низкий

6.1 Medium

CVSS3

6.8 Medium

CVSS3

Дефекты

CWE-200
CWE-668