CVE-2019-6140: Critical severity forcepoint email security vulnerability
Published Apr 9, 2019
·Updated
A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybrid registration process is not completed.
Affected Software
2 affected components
Forcepoint Email Security>=8.5<=8.5.3
Forcepoint Email Security=8.4
Event History
Apr 9, 2019
CVE Published
via MITRE·08:51 PM
Data Sourced
via MITRE·08:51 PM
DescriptionWeakness
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-6140.
2
What is the severity of CVE-2019-6140?
The severity of CVE-2019-6140 is critical (9.8).
3
Which software versions are affected by CVE-2019-6140?
The Forcepoint Email Security versions 8.4 and 8.5 (up to 8.5.3) are affected by CVE-2019-6140.
4
What is the issue with Forcepoint Email Security in CVE-2019-6140?
A configuration issue in Forcepoint Email Security can leave the product in a vulnerable state if the hybrid registration process is not completed.
5
Is there a fix for CVE-2019-6140?
Yes, Forcepoint has provided a fix for CVE-2019-6140. Please refer to the vendor's advisory for more information.