CVE-2020-25034: SQL Injection
Published Oct 26, 2020
·Updated
eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sortby, search{URL], or search[attachment] parameter to the email search feature.
Affected Software
2 affected components
FireEye Email Malware Protection System<9.0.1
FireEye EX 3500
Event History
Oct 26, 2020
CVE Published
via MITRE·06:42 PM
Data Sourced
via MITRE·06:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-25034?
CVE-2020-25034 is classified as a high severity vulnerability due to the potential for remote authenticated users to perform SQL injection attacks.
2
How do I fix CVE-2020-25034?
To mitigate CVE-2020-25034, upgrade your FireEye Email Malware Protection System to version 9.0.1 or later.
3
What type of vulnerability is CVE-2020-25034?
CVE-2020-25034 is categorized as an SQL injection vulnerability.
4
Which devices are affected by CVE-2020-25034?
CVE-2020-25034 affects FireEye Email Malware Protection Systems prior to version 9.0.1.
5
Can remote users exploit CVE-2020-25034?
Yes, remote authenticated users can exploit CVE-2020-25034 via specific parameters in the email search feature.