« Volver al listado

CVE-2023-0090

Estado: ModificadaCrítica (9.8)—

The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration. This affects all versions 8.20.0 and below.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-0090",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-0090",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-28T18:28:24.377984Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@proofpoint.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@proofpoint.com",
      "affectedData": [
        {
          "vendor": "proofpoint",
          "product": "enterprise_protection",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "8.20.0 patch 4570",
                  "status": "unaffected"
                },
                {
                  "at": "8.18.6 patch 4568",
                  "status": "unaffected"
                },
                {
                  "at": "8.18.4 patch 4567",
                  "status": "unaffected"
                },
                {
                  "at": "8.13.22 patch 4566",
                  "status": "unaffected"
                }
              ],
              "version": "8.*",
              "versionType": "semver",
              "lessThanOrEqual": "8.20.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-03-08T01:15:10.343",
  "references": [
    {
      "url": "https://www.proofpoint.com/security/security-advisories/pfpt-sa-2023-0001",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@proofpoint.com"
    },
    {
      "url": "https://www.proofpoint.com/security/security-advisories/pfpt-sa-2023-0001",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@proofpoint.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-95"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'.  Exploitation requires network access to the webservices API, but such access is a non-standard configuration.  This affects all versions 8.20.0 and below.\n\n"
    }
  ],
  "lastModified": "2026-06-17T05:24:45.467",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:proofpoint:enterprise_protection:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F25CC84-3AA4-4B66-8206-F26C14443A13",
              "versionEndExcluding": "8.13.22"
            },
            {
              "criteria": "cpe:2.3:a:proofpoint:enterprise_protection:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "202B7803-2398-41E7-B88B-2D64384ADC74",
              "versionEndExcluding": "8.18.4",
              "versionStartIncluding": "8.18.0"
            },
            {
              "criteria": "cpe:2.3:a:proofpoint:enterprise_protection:8.18.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E481ED5-1AC8-4FEA-9169-17CDE7AB93DA"
            },
            {
              "criteria": "cpe:2.3:a:proofpoint:enterprise_protection:8.20.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83C899EC-C3E7-4D34-8362-DEB40F16AD09"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@proofpoint.com"
}