PT-2020-10610 · Proofpoint · Proofpoint Email Protection
Nick Landers
+1
·
Published
2020-03-30
·
Updated
2024-08-19
·
CVE-2019-20634
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Proofpoint Email Protection versions prior to 2019-09-08
Description
An issue was discovered in Proofpoint Email Protection. By collecting scores from Proofpoint email headers, it is possible to build a copy-cat Machine Learning Classification model and extract insights from this model. The insights gathered allow an attacker to craft emails that receive preferable scores, with a goal of delivering malicious emails.
Recommendations
For versions prior to 2019-09-08, consider implementing additional email filtering rules to detect and block malicious emails that may have been crafted using the insights gathered from the Proofpoint email headers. As a temporary workaround, consider enhancing the email scoring system to make it more difficult for attackers to build a copy-cat Machine Learning Classification model.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Proofpoint Email Protection