Configuration Database Corruption in Forcepoint NGFW Security Management Center
CVE-2019-6147

5.9MEDIUM

Key Information:

Vendor

Forcepoint

Vendor
CVE Published:
23 December 2019

What is CVE-2019-6147?

The Forcepoint NGFW Security Management Center (SMC) has a vulnerability affecting versions prior to 6.5.12 and 6.7.1, which can lead to corruption of its internal configuration database. This rare issue may arise under specific circumstances, resulting in an incorrect IPsec configuration for the Forcepoint Next Generation Firewall (NGFW). As a result, the firewall settings may be weaker than intended, which could compromise the overall security posture of the network.

Affected Version(s)

NGFW Security Management Center Any version lower than 6.5.12 or 6.7.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.