SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-5131

The Receive Service in Websense Email Security before 7.1 does not recognize domain extensions in the blacklist, which allows remote attackers to bypass intended access restrictions and send e-mail messages via an SMTP session.

MEDIUM 5.0EPSS 1.43%

Does this matter?

Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.

Description

The Receive Service in Websense Email Security before 7.1 does not recognize domain extensions in the blacklist, which allows remote attackers to bypass intended access restrictions and send e-mail messages via an SMTP session.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.43% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
websense/websense email security
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.