CVE-2023-5451

EUVD-2023-57766
Forcepoint
 NGFW Security Management Center Management Server has SMC Downloads 
optional feature to offer standalone Management Client downloads and ECA
 configuration downloads.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS.

This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.

Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
forcepointCNA
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
forcepointnext_generation_firewall_security_management_center
𝑥
< 6.10.13
CNA
forcepointnext_generation_firewall_security_management_center
6.11.0 ≤
𝑥
< 7.1.2
CNA