An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All versions prior to 7.14.3.69 are affected. Agents for Windows, Linux, and Cloud are unaffected.
History

Wed, 25 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:proofpoint:insider_threat_management:-:*:*:*:*:macos:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Proofpoint

Published: 2023-09-13T15:14:36.165Z

Updated: 2024-09-25T17:38:58.900Z

Reserved: 2023-09-06T15:23:18.574Z

Link: CVE-2023-4801

cve-icon Vulnrichment

Updated: 2024-08-02T07:38:00.701Z

cve-icon NVD

Status : Modified

Published: 2023-09-13T16:15:10.767

Modified: 2024-11-21T08:35:59.690

Link: CVE-2023-4801

cve-icon Redhat

No data.