8.8
CVE-2019-19680
- EPSS 0.35%
- Veröffentlicht 13.01.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:10
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of PPS through 8.9.22 and 8.14.2 respectively, allows attackers to bypass protection mechanisms (related to extensions, MIME types, virus detection, and journal entries for transmitted files) by sending malformed (not RFC compliant) multipart email.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Proofpoint ≫ Enterprise Protection SwEditionlts Version <= 8.9.22
Proofpoint ≫ Enterprise Protection SwEdition- Version <= 8.14.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.57 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|