CVE-2023-36000
Summary
| CVE | CVE-2023-36000 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-27 15:15:00 UTC |
| Updated | 2023-07-06 16:12:00 UTC |
| Description | A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive information. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Macos | - | All | All | All |
| Application | Proofpoint | Insider Threat Management Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ITM Windows Agent Insecure Filesystem Permissions | Proofpoint US | MISC | www.proofpoint.com | |
| ITM Server Multiple Vulnerabilities | Proofpoint US | MISC | www.proofpoint.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.