Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services protected by the NGFW Engine. The vulnerability affects the following NGFW features when the LDAP authentication method is used as the backend authentication: IPsec VPN, SSL VPN or Browser-based user authentication. The vulnerability does not apply when any other backend authentication is used. The RADIUS authentication method is not vulnerable, for example.
Conclusion & alert: CVE-2019-6143 is rated Moderate Risk (59/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.13%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.27% | 1.13% | +0.86% |
| 2 | 2025-03-30 | 0.52% | 0.27% | -0.25% |
| 3 | 2025-03-29 | — | 0.52% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.1 | 3.1 | CRITICAL |
|
3.9 | 5.2 | [email protected] |
| 6.4 | 2.0 | MEDIUM |
|
10.0 | 4.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| forcepoint | next_generation_firewall | >= 6.4.0, < 6.4.7 | cpe:2.3:a:forcepoint:next_generation_firewall:*:*:*:*:*:*:*:* |
| forcepoint | next_generation_firewall | >= 6.5.0, < 6.5.4 | cpe:2.3:a:forcepoint:next_generation_firewall:*:*:*:*:*:*:*:* |
| forcepoint | next_generation_firewall | >= 6.6.0, < 6.6.2 | cpe:2.3:a:forcepoint:next_generation_firewall:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://help.forcepoint.com/security/CVE/CVE-2019-6143.html | Vendor Advisory |