ZeroHour

CVE-2023-36002

CVSS 3.1
4.3 medium
EPSS
<1%p17
Published
()
Modified
Description

A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected.

Vendors
proofpoint
Products
insider threat management server
Weakness
CWE-862
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.