CVE-2023-5451
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Forcepoint
NGFW Security Management Center Management Server has SMC Downloads
optional feature to offer standalone Management Client downloads and ECA
configuration downloads.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS.
This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.
Forcepoint NGFW Security Management Center Management Server tiene la función opcional Descargas SMC para ofrecer descargas independientes de Management Client y descargas de configuración ECA. La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('Scripting entre sitios') en el Centro de administración de seguridad del firewall de próxima generación de Forcepoint (función de descargas de SMC) permite XSS reflejado. Este problema afecta al Centro de administración de seguridad del firewall de próxima generación: antes de 6.10.13, desde 6.11.0 antes de 7.1.2.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-10-06 CVE Reserved
- 2024-03-04 CVE Published
- 2024-03-05 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
- CAPEC-591: Reflected XSS
References (1)
URL | Tag | Source |
---|---|---|
https://support.forcepoint.com/s/article/000042395 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Forcepoint Search vendor "Forcepoint" | Next Generation Firewall Security Management Center Search vendor "Forcepoint" for product "Next Generation Firewall Security Management Center" | < 6.10.13 Search vendor "Forcepoint" for product "Next Generation Firewall Security Management Center" and version " < 6.10.13" | en |
Affected
| ||||||
Forcepoint Search vendor "Forcepoint" | Next Generation Firewall Security Management Center Search vendor "Forcepoint" for product "Next Generation Firewall Security Management Center" | >= 6.11.0 < 7.1.2 Search vendor "Forcepoint" for product "Next Generation Firewall Security Management Center" and version " >= 6.11.0 < 7.1.2" | en |
Affected
|