CVE-2021-28970: SQL Injection
Published Apr 1, 2021
·Updated
eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the jobid parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3.
Affected Software
2 affected components
FireEye Email Malware Protection System=9.0.1.923211
FireEye EX 3500
Event History
Apr 1, 2021
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28970?
CVE-2021-28970 is categorized as a high severity vulnerability due to the potential for SQL injection attacks.
2
How do I fix CVE-2021-28970?
To fix CVE-2021-28970, upgrade the FireEye Email Malware Protection System to version 9.0.3 or higher.
3
Who is affected by CVE-2021-28970?
CVE-2021-28970 affects users of FireEye Email Malware Protection System version 9.0.1.923211.
4
What kind of attack can be executed using CVE-2021-28970?
CVE-2021-28970 allows remote authenticated users to perform SQL injection attacks via the job_id parameter.
5
Is there a known patch for CVE-2021-28970?
Yes, a patch is available in version 9.0.3 of the FireEye Email Malware Protection System.