Search

Find a vulnerability

Search criteria

    1 vulnerability found for insider_threat_management by proofpoint

    CVE-2023-4801 (GCVE-0-2023-4801)

    Vulnerability from cvelistv5 – Published: 2023-09-13 15:14 – Updated: 2024-09-25 17:38
    VLAI
    Title
    ITM MacOS Agent Improper Certificate Validation
    Summary
    An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All versions prior to 7.14.3.69 are affected. Agents for Windows, Linux, and Cloud are unaffected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-25 17:34 UTC
    CWE
    • CWE-295 - Improper Certificate Validation
    Impacted products
    Vendor Product Version
    Proofpoint Insider Threat Management Affected: 0 , ≤ 7.14.3 (semver)
    Create a notification for this product.
    proofpoint insider_threat_management Affected: 0 , ≤ 7.14.3.69 (custom)
        cpe:2.3:a:proofpoint:insider_threat_management:-:*:*:*:*:macos:*:*
    Create a notification for this product.
    Date Public
    2023-09-13 15:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:38:00.701Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-006"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:proofpoint:insider_threat_management:-:*:*:*:*:macos:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "insider_threat_management",
                "vendor": "proofpoint",
                "versions": [
                  {
                    "lessThanOrEqual": "7.14.3.69",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-4801",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-25T17:34:51.428379Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-25T17:38:58.900Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Agent"
              ],
              "platforms": [
                "MacOS"
              ],
              "product": "Insider Threat Management",
              "vendor": "Proofpoint",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "7.14.3.69",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "7.14.3",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "datePublic": "2023-09-13T15:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All versions prior to 7.14.3.69 are affected. Agents for Windows, Linux, and Cloud are unaffected."
                }
              ],
              "value": "An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All versions prior to 7.14.3.69 are affected. Agents for Windows, Linux, and Cloud are unaffected."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295 Improper Certificate Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-13T15:14:36.165Z",
            "orgId": "d83a79dd-e128-4b83-8b64-84faf54eed46",
            "shortName": "Proofpoint"
          },
          "references": [
            {
              "url": "https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-006"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "ITM MacOS Agent Improper Certificate Validation",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "d83a79dd-e128-4b83-8b64-84faf54eed46",
        "assignerShortName": "Proofpoint",
        "cveId": "CVE-2023-4801",
        "datePublished": "2023-09-13T15:14:36.165Z",
        "dateReserved": "2023-09-06T15:23:18.574Z",
        "dateUpdated": "2024-09-25T17:38:58.900Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }