Forcepoint
Published Mar 4, 2024
6.1
MEDIUMCVSS 3.1
EPSS 0.31%
Description
Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS.
This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.
Affected products
-
- Version 0StatusaffectedConstraints<6.10.13
- Version 6.11.0StatusaffectedConstraints<7.1.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Forcepoint | Next Generation Firewall Security Management Center | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The vulnerability has been fixed in the SMC releases 6.10.13 and 7.1.2.
References (2)
Change history (0)
No recorded changes yet.