Next Generation Firewall
CVE-2023-5451: Cross-site scripting in Next Generation Firewall Security Management Center
Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Next Generation Firewall Security Management Center 0 | 6.10.13 or later |
| Next Generation Firewall Security Management Center 6.11 | 7.1.2 or later |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS.
This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.
Workarounds
To limit the access to the SMC, Forcepoint recommends that the SMC deployment is placed in a dedicated, secure network segment without third-party servers and limited network access. Alternatively, Forcepoint recommends disabling Management Server SMC Downloads feature.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.