SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-25034

eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, search{URL], or search[attachment] parameter to the email search feature.

MEDIUM 6.5EPSS 1.42%

Does this matter?

Lower severity and a low EPSS score (1.42%). Track it; it rarely justifies an emergency change on its own.

Description

eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, search{URL], or search[attachment] parameter to the email search feature.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.42% probability · 71th percentile
CISA KEV
Not listed
Weakness
CWE-89
Affected
fireeye/email malware protection system
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.