Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-10635

Опубликовано: 28 апр. 2025
Источник: nvd
CVSS3: 6.1
CVSS3: 5.3
EPSS Низкий

Описание

Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending a malicious S/MIME attachment with an opaque signature. When opened by a recipient in a downstream email client, the malicious attachment could cause partial loss of integrity and confidentiality to their system.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:proofpoint:enterprise_protection:8.18.6:*:*:*:-:*:*:*
cpe:2.3:a:proofpoint:enterprise_protection:8.20.6:*:*:*:-:*:*:*
cpe:2.3:a:proofpoint:enterprise_protection:8.21.0:*:*:*:-:*:*:*

EPSS

Процентиль: 16%
0.0005
Низкий

6.1 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-754
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.1
github
9 месяцев назад

Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending a malicious S/MIME attachment with an opaque signature. When opened by a recipient in a downstream email client, the malicious attachment could cause partial loss of integrity and confidentiality to their system.

EPSS

Процентиль: 16%
0.0005
Низкий

6.1 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-754
NVD-CWE-noinfo