First published: Mon Dec 23 2019(Updated: )
Forcepoint NGFW Security Management Center (SMC) versions lower than 6.5.12 or 6.7.1 have a rare issue that in specific circumstances can corrupt the internal configuration database. When the database is corrupted, the SMC might produce an incorrect IPsec configuration for the Forcepoint Next Generation Firewall (NGFW), possibly resulting in settings that are weaker than expected. All SMC versions lower than 6.5.12 or 6.7.1 are vulnerable.
Credit: psirt@forcepoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Forcepoint Next Generation Firewall Security Management Center | <6.5.12 | |
Forcepoint Next Generation Firewall Security Management Center | >=6.6.0<6.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6147 is a vulnerability in Forcepoint NGFW Security Management Center (SMC) versions lower than 6.5.12 or 6.7.1 that can corrupt the internal configuration database under specific circumstances.
Users of Forcepoint NGFW Security Management Center (SMC) versions lower than 6.5.12 or 6.7.1 may experience corruption of the internal configuration database, leading to incorrect IPsec configurations.
CVE-2019-6147 has a severity rating of medium, with a severity value of 5.9.
Forcepoint NGFW Security Management Center versions lower than 6.5.12 or between 6.6.0 and 6.7.1 are affected by CVE-2019-6147.
To fix CVE-2019-6147, users should update their Forcepoint NGFW Security Management Center to version 6.5.12 or 6.7.1, depending on the current version.