« Volver al listado

CVE-2019-6147

Estado: ModificadaMedia (5.9)—

Forcepoint NGFW Security Management Center (SMC) versions lower than 6.5.12 or 6.7.1 have a rare issue that in specific circumstances can corrupt the internal configuration database. When the database is corrupted, the SMC might produce an incorrect IPsec configuration for the Forcepoint Next Generation Firewall (NGFW), possibly resulting in settings that are weaker than expected. All SMC versions lower than 6.5.12 or 6.7.1 are vulnerable.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-6147",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@forcepoint.com",
      "affectedData": [
        {
          "vendor": "Forcepoint",
          "product": "NGFW Security Management Center",
          "versions": [
            {
              "status": "affected",
              "version": "Any version lower than 6.5.12 or 6.7.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-12-23T20:15:11.157",
  "references": [
    {
      "url": "https://help.forcepoint.com/security/CVE/CVE-2019-6147.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@forcepoint.com"
    },
    {
      "url": "https://help.forcepoint.com/security/CVE/CVE-2019-6147.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-704"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Forcepoint NGFW Security Management Center (SMC) versions lower than 6.5.12 or 6.7.1 have a rare issue that in specific circumstances can corrupt the internal configuration database. When the database is corrupted, the SMC might produce an incorrect IPsec configuration for the Forcepoint Next Generation Firewall (NGFW), possibly resulting in settings that are weaker than expected. All SMC versions lower than 6.5.12 or 6.7.1 are vulnerable."
    },
    {
      "lang": "es",
      "value": "Forcepoint NGFW Security Management Center (SMC) versiones por debajo de 6.5.12 o 6.7.1, presenta un problema poco frecuente que, en circunstancias específicas, puede corromper la base de datos de la configuración interna. Cuando la base de datos está corrupta, el SMC puede producir una configuración IPsec incorrecta para el Forcepoint Next Generation Firewall (NGFW), resultando posiblemente en configuraciones más débiles de lo esperado. Todas las versiones de SMC por debajo de 6.5.12 o 6.7.1 son vulnerables."
    }
  ],
  "lastModified": "2026-06-17T02:38:41.047",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:forcepoint:next_generation_firewall_security_management_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8852D0CC-9341-49D0-BDB5-80889A7F4D0D",
              "versionEndExcluding": "6.5.12"
            },
            {
              "criteria": "cpe:2.3:a:forcepoint:next_generation_firewall_security_management_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE860675-CA71-40A6-83B6-7F4665ED0BF1",
              "versionEndExcluding": "6.7.1",
              "versionStartIncluding": "6.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@forcepoint.com"
}