Forcepoint
NGFW Security Management Center Management Server has SMC Downloads
optional feature to offer standalone Management Client downloads and ECA
configuration downloads.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS.

This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-57766 Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS. This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.
Fixes

Solution

The vulnerability has been fixed in the SMC releases 6.10.13 and 7.1.2.


Workaround

To limit the access to the SMC, Forcepoint recommends that the SMC deployment is placed in a dedicated, secure network segment without third-party servers and limited network access. Alternatively, Forcepoint recommends disabling Management Server SMC Downloads feature.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: forcepoint

Published:

Updated: 2024-08-02T07:59:44.679Z

Reserved: 2023-10-06T16:47:41.779Z

Link: CVE-2023-5451

cve-icon Vulnrichment

Updated: 2024-07-05T15:20:41.242Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-04T16:15:49.490

Modified: 2024-11-21T08:41:47.633

Link: CVE-2023-5451

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T21:07:35Z