---
cve: "CVE-2023-5451"
severity: "MEDIUM"
cvss: 6.1
epss: "31%"
vendor: "Forcepoint"
kev: false
exploited: false
published: "2024-03-04 16:15:49"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T08:55:34+02:00"
---

# CVE-2023-5451

> 6.1 MEDIUM

## Beschreibung

Forcepoint
 NGFW Security Management Center Management Server has SMC Downloads 
optional feature to offer standalone Management Client downloads and ECA
 configuration downloads.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall Security Management Center (SMC Downloads feature) allows Reflected XSS.

This issue affects Next Generation Firewall Security Management Center : before 6.10.13, from 6.11.0 before 7.1.2.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://support.forcepoint.com/s/article/000042395>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-5451) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
