CVE-2019-6147 affects Forcepoint NGFW Security Management Center (SMC) versions prior to 6.5.12 or 6.7.1. This vulnerability involves a rare issue where specific circumstances can corrupt the internal configuration database, leading to the SMC generating an incorrect and potentially weaker IPsec configuration for the Forcepoint Next Generation Firewall. The vulnerability has a CVSS score of 5.9 (Medium), indicating a network attack vector with high attack complexity and a high impact on integrity, but no impact on confidentiality or availability. The EPSS score is very low, suggesting a low likelihood of exploitation. There is no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and no community discussion or media coverage surrounding this CVE. It is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.5.12CPE matchmatch criteria | cpe:2.3:a:forcepoint:next_generation_firewall_security_management_center:*:*:*:*:*:*:*:* | ||
>= 6.6.0, < 6.7.1CPE matchmatch criteria | cpe:2.3:a:forcepoint:next_generation_firewall_security_management_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.