// For flags

CVE-2021-27899

 

Severity Score

7.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Server's certificate, which enables a remote attacker to intercept and alter these communications using a man-in-the-middle attack. All versions before 7.11.1 are affected. Agents for Windows and Cloud are not affected.

Los Agentes Proofpoint Insider Threat Management (anteriormente ObserveIT Agent) para MacOS y Linux llevan a cabo una comprobación inapropiada del certificado del servidor ITM, lo que permite a un atacante remoto interceptar y alterar estas comunicaciones usando un ataque de tipo man-in-the-middle. Todas las versiones anteriores a 7.11.1 están afectadas. Los agentes para Windows y Cloud no están afectados

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-03-02 CVE Reserved
  • 2021-04-06 CVE Published
  • 2024-04-09 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-295: Improper Certificate Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Proofpoint
Search vendor "Proofpoint"
Insider Threat Management
Search vendor "Proofpoint" for product "Insider Threat Management"
>= 7.9.0 < 7.9.3
Search vendor "Proofpoint" for product "Insider Threat Management" and version " >= 7.9.0 < 7.9.3"
linux
Affected
Proofpoint
Search vendor "Proofpoint"
Insider Threat Management
Search vendor "Proofpoint" for product "Insider Threat Management"
>= 7.10.0 < 7.10.3
Search vendor "Proofpoint" for product "Insider Threat Management" and version " >= 7.10.0 < 7.10.3"
linux
Affected
Proofpoint
Search vendor "Proofpoint"
Insider Threat Management
Search vendor "Proofpoint" for product "Insider Threat Management"
>= 7.11.0 < 7.11.1
Search vendor "Proofpoint" for product "Insider Threat Management" and version " >= 7.11.0 < 7.11.1"
linux
Affected
Proofpoint
Search vendor "Proofpoint"
Insider Threat Management
Search vendor "Proofpoint" for product "Insider Threat Management"
>= 7.9.0 < 7.9.3
Search vendor "Proofpoint" for product "Insider Threat Management" and version " >= 7.9.0 < 7.9.3"
macos
Affected
Proofpoint
Search vendor "Proofpoint"
Insider Threat Management
Search vendor "Proofpoint" for product "Insider Threat Management"
>= 7.10.0 < 7.10.3
Search vendor "Proofpoint" for product "Insider Threat Management" and version " >= 7.10.0 < 7.10.3"
macos
Affected
Proofpoint
Search vendor "Proofpoint"
Insider Threat Management
Search vendor "Proofpoint" for product "Insider Threat Management"
>= 7.11.0 < 7.11.1
Search vendor "Proofpoint" for product "Insider Threat Management" and version " >= 7.11.0 < 7.11.1"
macos
Affected