Next Generation Firewall
CVE-2019-6139: Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload in Forcepoint User ID (FUID) server
Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Forcepoint User ID (FUID) server Forcepoint User ID (FUID) server versions up to 1.2 | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. Successful exploitation of this vulnerability may lead to remote code execution. To fix this vulnerability, upgrade to FUID version 1.3 or higher. To prevent the vulnerability on FUID versions 1.2 and below, apply local firewall rules on the FUID server to disable all external access to port TCP/5001. FUID requires this port only for local connections through the loopback interface.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.