First published: Wed Sep 13 2023(Updated: )
An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the agent and the ITM server after the agent has registered. All versions prior to 7.14.3.69 are affected. Agents for Windows, Linux, and Cloud are unaffected.
Credit: security@proofpoint.com security@proofpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Proofpoint Insider Threat Management | <7.14.3.69 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4801 is an improper certification validation vulnerability in the Proofpoint Insider Threat Management (ITM) Agent for MacOS.
An attacker on an adjacent network can establish a man-in-the-middle position between the ITM Agent and the ITM server after the agent has registered.
All versions prior to 7.14.3.69 of the ITM Agent for MacOS are affected.
To fix CVE-2023-4801, update the ITM Agent for MacOS to version 7.14.3.69 or later.
CVE-2023-4801 has a severity rating of high, with a CVSS score of 7.5.