CVE-2023-5451
https://notcve.org/view.php?id=CVE-2023-5451
Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS. This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2. Forcepoint NGFW Security Management Center Management Server tiene la función opcional Descargas SMC para ofrecer descargas independientes de Management Client y descargas de configuración ECA. La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('Scripting entre sitios') en el Centro de administración de seguridad del firewall de próxima generación de Forcepoint (función de descargas de SMC) permite XSS reflejado. Este problema afecta al Centro de administración de seguridad del firewall de próxima generación: antes de 6.10.13, desde 6.11.0 antes de 7.1.2. • https://support.forcepoint.com/s/article/000042395 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-6147
https://notcve.org/view.php?id=CVE-2019-6147
Forcepoint NGFW Security Management Center (SMC) versions lower than 6.5.12 or 6.7.1 have a rare issue that in specific circumstances can corrupt the internal configuration database. When the database is corrupted, the SMC might produce an incorrect IPsec configuration for the Forcepoint Next Generation Firewall (NGFW), possibly resulting in settings that are weaker than expected. All SMC versions lower than 6.5.12 or 6.7.1 are vulnerable. Forcepoint NGFW Security Management Center (SMC) versiones por debajo de 6.5.12 o 6.7.1, presenta un problema poco frecuente que, en circunstancias específicas, puede corromper la base de datos de la configuración interna. Cuando la base de datos está corrupta, el SMC puede producir una configuración IPsec incorrecta para el Forcepoint Next Generation Firewall (NGFW), resultando posiblemente en configuraciones más débiles de lo esperado. • https://help.forcepoint.com/security/CVE/CVE-2019-6147.html • CWE-704: Incorrect Type Conversion or Cast •