Description
Forcepoint
NGFW Security Management Center Management Server has SMC Downloads
optional feature to offer standalone Management Client downloads and ECA
configuration downloads.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS.

This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.

Published: 2024-03-04
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

The vulnerability has been fixed in the SMC releases 6.10.13 and 7.1.2.


Vendor Workaround

To limit the access to the SMC, Forcepoint recommends that the SMC deployment is placed in a dedicated, secure network segment without third-party servers and limited network access. Alternatively, Forcepoint recommends disabling Management Server SMC Downloads feature.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-57766 Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS. This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.
History

No history.

Subscriptions

Forcepoint Next Generation Firewall Security Management Center
cve-icon MITRE

Status: PUBLISHED

Assigner: forcepoint

Published:

Updated: 2024-08-02T07:59:44.679Z

Reserved: 2023-10-06T16:47:41.779Z

Link: CVE-2023-5451

cve-icon Vulnrichment

Updated: 2024-07-05T15:20:41.242Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-04T16:15:49.490

Modified: 2024-11-21T08:41:47.633

Link: CVE-2023-5451

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T21:07:35Z

Weaknesses