PT-2020-10610 · Proofpoint · Proofpoint Email Protection

Nick Landers

+1

·

Published

2020-03-30

·

Updated

2024-08-19

·

CVE-2019-20634

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Proofpoint Email Protection versions prior to 2019-09-08
Description An issue was discovered in Proofpoint Email Protection. By collecting scores from Proofpoint email headers, it is possible to build a copy-cat Machine Learning Classification model and extract insights from this model. The insights gathered allow an attacker to craft emails that receive preferable scores, with a goal of delivering malicious emails.
Recommendations For versions prior to 2019-09-08, consider implementing additional email filtering rules to detect and block malicious emails that may have been crafted using the insights gathered from the Proofpoint email headers. As a temporary workaround, consider enhancing the email scoring system to make it more difficult for attackers to build a copy-cat Machine Learning Classification model.

Fix

Weakness Enumeration

Related Identifiers

CVE-2019-20634

Affected Products

Proofpoint Email Protection