CVE-2020-25034: Fireeye Email Malware Protection System

Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.

eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, search{URL], or search[attachment] parameter to the email search feature.

Affected products

  • Fireeye Email Malware Protection System: before 9.0.1 (fixed in 9.0.1)

Published 2020-10-26. Last modified 2026-06-17.