CVE-2025-0431 Details
Description
Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integrity of recipient's email. This occurs due to improper filtering of backslashes within URLs and affects all versions of 8.21, 8.20 and 8.18 prior to 8.21.0 patch 5115, 8.20.6 patch 5114 and 8.18.6 patch 5113 respectively.
A vulnerability exists in Proofpoint Enterprise Protection's URL rewriting process, allowing an unauthenticated remote attacker to send emails that bypass URL protections. This flaw, which impacts the integrity of the recipient's email, arises from inadequate filtering of backslashes in URLs. The vulnerability affects all versions of 8.21, 8.20, and 8.18 prior to their respective patched releases.
Proofpoint has released patches for this vulnerability in versions 8.18.6 patch 5113, 8.20.6 patch 5114, and 8.21.0 patch 5115. On-premises customers should upgrade to these versions. Proofpoint On-Demand customers do not need to take any action, as the fixes have already been deployed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 19, 2025CISA-ADP
Assessed Mar 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2025-0001 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-790 | Improper Filtering of Special Elements | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Proofpoint Enterprise Protection | < 8.21.0 patch 5115 < 8.20.6 patch 5114 < 8.18.6 patch 5113 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 19, 2025 | New CVE Received | [email protected] |
Volerion