First published: Mon Oct 26 2020(Updated: )
eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, search{URL], or search[attachment] parameter to the email search feature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FireEye Email Malware Protection System | <9.0.1 | |
Fireeye EX 3500 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25034 is classified as a high severity vulnerability due to the potential for remote authenticated users to perform SQL injection attacks.
To mitigate CVE-2020-25034, upgrade your FireEye Email Malware Protection System to version 9.0.1 or later.
CVE-2020-25034 is categorized as an SQL injection vulnerability.
CVE-2020-25034 affects FireEye Email Malware Protection Systems prior to version 9.0.1.
Yes, remote authenticated users can exploit CVE-2020-25034 via specific parameters in the email search feature.