Lucene search

K
cvelistProofpointCVELIST:CVE-2023-0090
HistoryMar 08, 2023 - 12:27 a.m.

CVE-2023-0090 Proofpoint Enterprise Protection webservices unauthenticated RCE

2023-03-0800:27:36
CWE-95
Proofpoint
www.cve.org
3
proofpoint enterprise protection
webservices
unauthenticated rce
vulnerability
versions 8.20.0

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.002

Percentile

52.3%

The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through ‘eval injection’. Exploitation requires network access to the webservices API, but such access is a non-standard configuration. This affects all versions 8.20.0 and below.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "enterprise_protection",
    "vendor": "proofpoint",
    "versions": [
      {
        "changes": [
          {
            "at": "8.20.0 patch 4570",
            "status": "unaffected"
          },
          {
            "at": "8.18.6 patch 4568",
            "status": "unaffected"
          },
          {
            "at": "8.18.4 patch 4567",
            "status": "unaffected"
          },
          {
            "at": "8.13.22 patch 4566",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "8.20.0",
        "status": "affected",
        "version": "8.*",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.002

Percentile

52.3%

Related for CVELIST:CVE-2023-0090