CVE-2021-41530: High severity Forcepoint Next Generation Firewall vulnerability
Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplification vulnerability, if HTTP User Response has been configured.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If HTTP User Response has been configured, disable it to prevent TCP reflected amplification vulnerability exposure on affected Forcepoint NGFW Engine versions.
Forcepoint NGFW Engine HTTP User Response = disabled
Event History
Frequently Asked Questions
What is CVE-2021-41530?
CVE-2021-41530 is a vulnerability in Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 that allows for TCP reflected amplification if HTTP User Response has been configured.
How does CVE-2021-41530 impact Forcepoint Next Generation Firewall?
CVE-2021-41530 can be used to exploit a TCP reflected amplification vulnerability in Forcepoint Next Generation Firewall versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0.
What is the severity of CVE-2021-41530?
CVE-2021-41530 has a severity rating of 7.5 (High).
How can I fix CVE-2021-41530?
To fix CVE-2021-41530, it is recommended to upgrade to Forcepoint NGFW Engine version 6.10.1 or later.
Where can I find more information about CVE-2021-41530?
More information about CVE-2021-41530 can be found on the Forcepoint help page: [https://help.forcepoint.com/security/CVE/CVE-2021-41530.html](https://help.forcepoint.com/security/CVE/CVE-2021-41530.html)