Vulnerability Description
The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Server's certificate, which enables a remote attacker to intercept and alter these communications using a man-in-the-middle attack. All versions before 7.11.1 are affected. Agents for Windows and Cloud are not affected.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Proofpoint | Insider Threat Management | >= 7.9.0, < 7.9.3 |
Related Weaknesses (CWE)
References
- https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2021-0004Vendor Advisory
- https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2021-0004Vendor Advisory
FAQ
What is CVE-2021-27899?
CVE-2021-27899 is a vulnerability with a CVSS score of 7.4 (HIGH). The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Server's certificate, which enables a remote attacker to intercept...
How severe is CVE-2021-27899?
CVE-2021-27899 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27899?
Check the references section above for vendor advisories and patch information. Affected products include: Proofpoint Insider Threat Management.