5.8
CVE-2025-0431
- EPSS 0.39%
- Veröffentlicht 19.03.2025 16:18:23
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle security@proofpoint.com
- CVE-Watchlists
- Unerledigt
Enterprise Protection Backslash URL Rewrite Bypass
Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integrity of recipient's email. This occurs due to improper filtering of backslashes within URLs and affects all versions of 8.21, 8.20 and 8.18 prior to 8.21.0 patch 5115, 8.20.6 patch 5114 and 8.18.6 patch 5113 respectively.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerProofpoint
≫
Produkt
Enterprise Protection
Default Statusaffected
Version
8.18.6
Version <
patch 5113
Status
affected
Version
8.20.6
Version <
patch 5114
Status
affected
Version
8.21.0
Version <
patch 5115
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.301 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@proofpoint.com | 5.8 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
|
CWE-790 Improper Filtering of Special Elements
The product receives data from an upstream component, but does not filter or incorrectly filters special elements before sending it to a downstream component.
https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2025-0001