{"api_version":"1","generated_at":"2026-04-23T08:04:02+00:00","cve":"CVE-2018-16529","urls":{"html":"https://cve.report/CVE-2018-16529","api":"https://cve.report/api/cve/CVE-2018-16529.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-16529","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-16529"},"summary":{"title":"CVE-2018-16529","description":"A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has already been used to reset a password.","state":"PUBLIC","assigner":"psirt@forcepoint.com","published_at":"2019-03-28 17:29:00","updated_at":"2022-04-22 19:24:00"},"problem_types":["CWE-640"],"metrics":[],"references":[{"url":"https://seclists.org/fulldisclosure/2018/Nov/23","name":"https://seclists.org/fulldisclosure/2018/Nov/23","refsource":"MISC","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"Full Disclosure: Security issue in the password reset mechanism of Forcepoint Secure Messaging product (tested in version 8.5)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://help.forcepoint.com/security/CVE/CVE-2018-16529.html","name":"https://help.forcepoint.com/security/CVE/CVE-2018-16529.html","refsource":"CONFIRM","tags":[],"title":"Security Advisory: Email Security Password Reset Link Expiration Vulnerability (CVE-2018-16529)","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://support.forcepoint.com/KBArticle?id=000016655","name":"https://support.forcepoint.com/KBArticle?id=000016655","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"KB Article | Forcepoint Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-16529","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-16529","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"16529","vulnerable":"1","versionEndIncluding":"8.5.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"forcepoint","cpe5":"email_security","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2018-16529","ASSIGNER":"psirt@forcepoint.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Forcepoint","product":{"product_data":[{"product_name":"Forcepoint Email Security","version":{"version_data":[{"version_value":"8.5.x"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-640: Weak Password Recovery Mechanism for Forgotten Password"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://seclists.org/fulldisclosure/2018/Nov/23","url":"https://seclists.org/fulldisclosure/2018/Nov/23"},{"refsource":"CONFIRM","name":"https://help.forcepoint.com/security/CVE/CVE-2018-16529.html","url":"https://help.forcepoint.com/security/CVE/CVE-2018-16529.html"}]},"description":{"description_data":[{"lang":"eng","value":"A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has already been used to reset a password."}]}},"nvd":{"publishedDate":"2019-03-28 17:29:00","lastModifiedDate":"2022-04-22 19:24:00","problem_types":["CWE-640"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:forcepoint:email_security:*:*:*:*:*:*:*:*","versionStartIncluding":"8.5.0","versionEndIncluding":"8.5.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"16529","Ordinal":"133322","Title":"CVE-2018-16529","CVE":"CVE-2018-16529","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"16529","Ordinal":"1","NoteData":"A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has already been used to reset a password.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"16529","Ordinal":"2","NoteData":"2019-03-28","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"16529","Ordinal":"3","NoteData":"2021-09-10","Type":"Other","Title":"Modified"}]}}}