5.8
CVE-2025-0431
- EPSS 0.07%
- Veröffentlicht 19.03.2025 16:18:23
- Zuletzt bearbeitet 19.03.2025 17:15:41
- Quelle security@proofpoint.com
- CVE-Watchlists
- Unerledigt
Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integrity of recipient's email. This occurs due to improper filtering of backslashes within URLs and affects all versions of 8.21, 8.20 and 8.18 prior to 8.21.0 patch 5115, 8.20.6 patch 5114 and 8.18.6 patch 5113 respectively.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerProofpoint
≫
Produkt
Enterprise Protection
Default Statusaffected
Version <
patch 5113
Version
8.18.6
Status
affected
Version <
patch 5114
Version
8.20.6
Status
affected
Version <
patch 5115
Version
8.21.0
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.215 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@proofpoint.com | 5.8 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
|
CWE-790 Improper Filtering of Special Elements
The product receives data from an upstream component, but does not filter or incorrectly filters special elements before sending it to a downstream component.