Remote Arbitrary File Upload Vulnerability in Forcepoint User ID Server
CVE-2019-6139
9.8CRITICAL
What is CVE-2019-6139?
The Forcepoint User ID (FUID) server includes a vulnerability that allows for remote arbitrary file uploads via TCP port 5001 in versions up to 1.2. If exploited, attackers may execute remote code on the server, which compromises system integrity. Users are advised to upgrade to FUID version 1.3 or higher to mitigate this risk. For those using FUID versions 1.2 or lower, imposing local firewall rules to restrict external access to TCP port 5001 can help prevent exploitation, as this port is solely intended for local use.
Affected Version(s)
Forcepoint User ID (FUID) server Forcepoint User ID (FUID) server versions up to 1.2