Back

MEDIUM

Forcepoint

Published Mar 4, 2024

Description

Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS.

This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.

Affected products

Remediation

Vendor solution

The vulnerability has been fixed in the SMC releases 6.10.13 and 7.1.2.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner forcepoint
Published Mar 4, 2024
Updated Aug 2, 2024
Reserved Oct 6, 2023
CISA Vulnrichment
Updated Mar 4, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner forcepoint
Published Mar 4, 2024
Updated Aug 2, 2024
Exploited since n/a
EUVD-2023-57766