CVE-2020-14009
MEDIUMProofpoint Enterprise Protection <8.16.4 - Info Disclosure
Title source: llmDescription
Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-blocking rules. The vulnerability exists because messages with certain crafted and malformed multipart structures are not properly handled.
Scores
CVSS v3
6.3
EPSS
0.0009
EPSS Percentile
25.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Details
CWE
CWE-354
Status
published
Products (1)
proofpoint/enterprise_protection
< 8.13.16
Published
May 07, 2021
Tracked Since
Feb 18, 2026