Remote Arbitrary File Upload Vulnerability in Forcepoint User ID Server
CVE-2019-6139

9.8CRITICAL

Key Information:

Vendor
CVE Published:
24 January 2019

What is CVE-2019-6139?

The Forcepoint User ID (FUID) server includes a vulnerability that allows for remote arbitrary file uploads via TCP port 5001 in versions up to 1.2. If exploited, attackers may execute remote code on the server, which compromises system integrity. Users are advised to upgrade to FUID version 1.3 or higher to mitigate this risk. For those using FUID versions 1.2 or lower, imposing local firewall rules to restrict external access to TCP port 5001 can help prevent exploitation, as this port is solely intended for local use.

Affected Version(s)

Forcepoint User ID (FUID) server Forcepoint User ID (FUID) server versions up to 1.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-6139 : Remote Arbitrary File Upload Vulnerability in Forcepoint User ID Server