CVE-2019-19680
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of PPS through 8.9.22 and 8.14.2 respectively, allows attackers to bypass protection mechanisms (related to extensions, MIME types, virus detection, and journal entries for transmitted files) by sending malformed (not RFC compliant) multipart email.
Una vulnerabilidad de filtrado de extensiones de archivos en Proofpoint Enterprise Protection (PPS / PoD), en las versiones sin parches de PPS a través de 8.9.22 y 8.14.2 respectivamente, permite a los atacantes eludir los mecanismos de protección (relacionados con extensiones, tipos MIME, detección de virus y entradas de diario para archivos transmitidos) mediante el envío de correo electrónico multiparte con formato incorrecto (no compatible con RFC).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-12-09 CVE Reserved
- 2020-01-13 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.proofpoint.com/us/security/cve-2019-19680 | 2021-03-04 | |
https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2020-0001 | 2021-03-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Proofpoint Search vendor "Proofpoint" | Enterprise Protection Search vendor "Proofpoint" for product "Enterprise Protection" | <= 8.9.22 Search vendor "Proofpoint" for product "Enterprise Protection" and version " <= 8.9.22" | lts |
Affected
| ||||||
Proofpoint Search vendor "Proofpoint" | Enterprise Protection Search vendor "Proofpoint" for product "Enterprise Protection" | <= 8.14.2 Search vendor "Proofpoint" for product "Enterprise Protection" and version " <= 8.14.2" | - |
Affected
|