The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's control. These accounts are able to send spoofed email to any users within the domains configured by the Administrator.
References
Configurations
No configuration.
History
14 May 2024, 19:17
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-14 19:15
Updated : 2024-05-14 19:17
NVD link : CVE-2024-3676
Mitre link : CVE-2024-3676
CVE.ORG link : CVE-2024-3676
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation