SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-28970

eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the job_id parameter to the email search feature.

MEDIUM 6.5EPSS 1.32%

Does this matter?

Lower severity and a low EPSS score (1.32%). Track it; it rarely justifies an emergency change on its own.

Description

eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the job_id parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.32% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-89
Affected
fireeye/email malware protection system
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.