Lucene search

K
cve[email protected]CVE-2023-5770
HistoryJan 09, 2024 - 10:15 p.m.

CVE-2023-5770

2024-01-0922:15:43
CWE-838
web.nvd.nist.gov
14
proofpoint
enterprise
protection
email
delivery agent
vulnerability
cve-2023-5770
nvd
security
patch 4809
patch 4805
patch 4804

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.5%

Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated attacker to inject improperly encoded HTML into the email body of a message through the email subject. The vulnerability is caused by inappropriate encoding when rewriting the email before delivery.This issue affects Proofpoint Enterprise Protection: from 8.20.2 before patch 4809, from 8.20.0 before patch 4805, from 8.18.6 before patch 4804 and all other prior versions.

Affected configurations

NVD
Node
proofpointenterprise_protectionMatch8.18.6
OR
proofpointenterprise_protectionMatch8.20.0
OR
proofpointenterprise_protectionMatch8.20.2

CNA Affected

[
  {
    "defaultStatus": "affected",
    "modules": [
      "Email Delivery Agent"
    ],
    "product": "Proofpoint Enterprise Protection",
    "vendor": "Proofpoint",
    "versions": [
      {
        "changes": [
          {
            "at": "patch 4809",
            "status": "unaffected"
          }
        ],
        "lessThan": "patch 4809",
        "status": "affected",
        "version": "8.20.2",
        "versionType": "semver"
      },
      {
        "changes": [
          {
            "at": "patch 4805",
            "status": "unaffected"
          }
        ],
        "lessThan": "patch 4805",
        "status": "affected",
        "version": "8.20.0",
        "versionType": "semver"
      },
      {
        "changes": [
          {
            "at": "patch 4804",
            "status": "unaffected"
          }
        ],
        "lessThan": "patch 4804",
        "status": "affected",
        "version": "8.18.6",
        "versionType": "semver"
      },
      {
        "lessThan": "8.18.6",
        "status": "affected",
        "version": "8.0",
        "versionType": "semver"
      }
    ]
  }
]

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.5%

Related for CVE-2023-5770