An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All versions prior to 7.14.3.69 are affected. Agents for Windows, Linux, and Cloud are unaffected.
References
| Link | Resource |
|---|---|
| https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-0006 | Vendor Advisory |
| https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-006 | Broken Link |
Configurations
History
No history.
Information
Published : 2023-09-13 16:15
Updated : 2023-09-15 19:06
NVD link : CVE-2023-4801
Mitre link : CVE-2023-4801
CVE.ORG link : CVE-2023-4801
JSON object : View
Products Affected
proofpoint
- insider_threat_management
CWE
CWE-295
Improper Certificate Validation
