NGFW Security Management Center Management Server has SMC Downloads
optional feature to offer standalone Management Client downloads and ECA
configuration downloads.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS.
This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57766 | Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS. This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2. |
Solution
The vulnerability has been fixed in the SMC releases 6.10.13 and 7.1.2.
Workaround
To limit the access to the SMC, Forcepoint recommends that the SMC deployment is placed in a dedicated, secure network segment without third-party servers and limited network access. Alternatively, Forcepoint recommends disabling Management Server SMC Downloads feature.
| Link | Providers |
|---|---|
| https://support.forcepoint.com/s/article/000042395 |
|
No history.
Status: PUBLISHED
Assigner: forcepoint
Published:
Updated: 2024-08-02T07:59:44.679Z
Reserved: 2023-10-06T16:47:41.779Z
Link: CVE-2023-5451
Updated: 2024-07-05T15:20:41.242Z
Status : Awaiting Analysis
Published: 2024-03-04T16:15:49.490
Modified: 2024-11-21T08:41:47.633
Link: CVE-2023-5451
No data.
OpenCVE Enrichment
Updated: 2025-07-13T21:07:35Z
EUVD