Lucene search

K
cveForcepointCVE-2019-6142
HistoryNov 05, 2019 - 9:15 p.m.

CVE-2019-6142

2019-11-0521:15:13
CWE-79
forcepoint
web.nvd.nist.gov
23
2
cve-2019-6142
xss
forcepoint email security
hotfix

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

33.8%

It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3. It is strongly recommended that you apply the relevant hotfix in order to remediate this issue.

Affected configurations

Nvd
Node
forcepointemail_securityMatch8.5
OR
forcepointemail_securityMatch8.5.3
OR
forcepointsecurity_managerMatch8.5
OR
forcepointsecurity_managerMatch8.5.3
VendorProductVersionCPE
forcepointemail_security8.5cpe:2.3:a:forcepoint:email_security:8.5:*:*:*:*:*:*:*
forcepointemail_security8.5.3cpe:2.3:a:forcepoint:email_security:8.5.3:*:*:*:*:*:*:*
forcepointsecurity_manager8.5cpe:2.3:a:forcepoint:security_manager:8.5:*:*:*:*:*:*:*
forcepointsecurity_manager8.5.3cpe:2.3:a:forcepoint:security_manager:8.5.3:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Forcepoint Email Security",
    "vendor": "Forcepoint",
    "versions": [
      {
        "status": "affected",
        "version": "8.5"
      },
      {
        "status": "affected",
        "version": "8.5.3"
      }
    ]
  }
]

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

33.8%

Related for CVE-2019-6142