Authentication Bypass in Forcepoint Next Generation Firewall
CVE-2019-6143

9.1CRITICAL

Key Information:

Vendor

Forcepoint

Vendor
CVE Published:
20 August 2019

What is CVE-2019-6143?

The Forcepoint Next Generation Firewall exhibits a significant vulnerability that permits unauthorized users to bypass the password authentication system. This affects key functionalities of the NGFW when using LDAP as the authentication backend, including IPsec VPN and SSL VPN services, as well as browser-based authentication. Users relying on other authentication methods, such as RADIUS, are not impacted by this issue. This security flaw necessitates prompt attention to safeguard network resources.

Affected Version(s)

Forcepoint Next Generation Firewall 6.4.0 - 6.4.6

Forcepoint Next Generation Firewall 6.5.0 - 6.5.3

Forcepoint Next Generation Firewall 6.6.0 - 6.6.1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-6143 : Authentication Bypass in Forcepoint Next Generation Firewall