CVE-2023-4828

An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the server's configuration of any already-registered agent so that the agent sends all future communications to an attacker-chosen URL. This could result in disclosure of sensitive data events from the agent about the personally identifiable information (PII) and intellectual property it monitors, and all such data could be altered or deleted before reaching the ITM Server. An attacker must first successfully obtain valid agent credentials and agent hostname. All versions prior to 7.14.3.69 are affected.
Configurations

Configuration 1 (hide)

cpe:2.3:a:proofpoint:insider_threat_management:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.2
v2 : unknown
v3 : 6.4
References () https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-008 - Broken Link () https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-008 - Broken Link

13 Oct 2023, 22:15

Type Values Removed Values Added
Summary An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the configuration of any already-registered agent so that all future agent communications are sent to an attacker-chosen URL. An attacker must first successfully obtain valid agent credentials and target agent hostname. All versions prior to 7.14.3.69 are affected. An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the server's configuration of any already-registered agent so that the agent sends all future communications to an attacker-chosen URL. This could result in disclosure of sensitive data events from the agent about the personally identifiable information (PII) and intellectual property it monitors, and all such data could be altered or deleted before reaching the ITM Server. An attacker must first successfully obtain valid agent credentials and agent hostname. All versions prior to 7.14.3.69 are affected.

15 Sep 2023, 19:08

Type Values Removed Values Added
CPE cpe:2.3:a:proofpoint:insider_threat_management:*:*:*:*:*:*:*:*
CWE CWE-754
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.2
First Time Proofpoint insider Threat Management
Proofpoint
References
  • (MISC) https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-0008 - Vendor Advisory
References (MISC) https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-008 - (MISC) https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2023-008 - Broken Link

13 Sep 2023, 16:34

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-13 16:15

Updated : 2024-11-21 08:36


NVD link : CVE-2023-4828

Mitre link : CVE-2023-4828

CVE.ORG link : CVE-2023-4828


JSON object : View

Products Affected

proofpoint

  • insider_threat_management
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions