Description
The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's control.  These accounts are able to send spoofed email to any users within the domains configured by the Administrator.
Published: 2024-05-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-32251 The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's control.  These accounts are able to send spoofed email to any users within the domains configured by the Administrator.
History

No history.

Subscriptions

Proofpoint Enterprise Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: Proofpoint

Published:

Updated: 2024-08-01T20:19:59.948Z

Reserved: 2024-04-11T20:00:59.260Z

Link: CVE-2024-3676

cve-icon Vulnrichment

Updated: 2024-08-01T20:19:59.948Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-14T19:15:12.970

Modified: 2024-11-21T09:30:09.570

Link: CVE-2024-3676

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T11:22:33Z

Weaknesses