PoC Index

CVE-2018-16529

CRITICAL 9.8EPSS 1.6%

A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has already been used to reset a password.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.56% chance of exploitation in the next 30 days, 73th percentile
Published
2019-03-28
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related