CVE-2019-19680

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/01/2020
Last modified:
04/03/2021

Description

A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of PPS through 8.9.22 and 8.14.2 respectively, allows attackers to bypass protection mechanisms (related to extensions, MIME types, virus detection, and journal entries for transmitted files) by sending malformed (not RFC compliant) multipart email.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:proofpoint:enterprise_protection:*:*:*:*:lts:*:*:* 8.9.22 (including)
cpe:2.3:a:proofpoint:enterprise_protection:*:*:*:*:-:*:*:* 8.14.2 (including)