Release notes for update package 1251-5242

This update package improves the detection capabilities of the Forcepoint NGFW system.

RELEASE DATE:    Friday May 15, 2020
MD5 CHECKSUM:    1a9443a4d1e63d050fcb1d3b62864ab0
SHA1 CHECKSUM:    8fce5583f89ca84477609df98032fadc372e28eb
SHA256 CHECKSUM:    97f757d1ce6ebd85a66d6263fd21f77b254f272bc59b8f9ce7f0cdfd5ecffe5d

UPDATE CRITICALITY:    MODERATE

MINIMUM SOFTWARE VERSIONS
- Forcepoint NGFW Security Management Center:    5.10.1.10027
- Forcepoint NGFW:    5.5.1.9848

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

Updated detected attacks:

TCP Client Stream Unknown

RiskVulnerability/SituationReferencesRelated FingerprintSituation TypeChange Description
High Cisco-Security-Manager-Rmi-Insecure-Deserialization CVE-2019-12630 Generic_CS-Cisco-Security-Manager-Rmi-Insecure-Deserialization Suspected Compromise
Fingerprint regexp changed

Text File Stream

RiskVulnerability/SituationReferencesRelated FingerprintSituation TypeChange Description
High JavaScript-Obfuscation No CVE/CAN File-Text_JavaScript-String-Value-Obfuscation Suspected Attack Related Anomalies
Fingerprint regexp changed

LIST OF OTHER CHANGES:

Updated objects:

TypeNameChanges
Network ElementTOR exit nodes
IPListTOR relay nodes IP Address List
IPListTOR exit nodes IP Address List

ACTIVATING THE UPDATE PACKAGE

  1. Ensure that the SHA256 checksum of the update package are correct.
  2. Open Admin Tools in the SMC GUI client.
  3. Right-click on the Updates folder and select "Import Update Packages".
  4. Right-click on the imported package and select Activate.
  5. Reinstall the system policy to take the changes into use. Custom policies may require manual updating.

DISCLAIMER AND COPYRIGHT

The information in this document is provided only for educational purposes and for the convenience of Forcepoint customers. The information contained herein is subject to change without notice, and is provided "AS IS" without guarantee or warranty as to the accuracy or applicability of the information to any specific situation, circumstance, or system configuration - use at your own risk. Forcepoint does not warrant or endorse any third-party products described herein.

Forcepoint™ is a trademark of Forcepoint, LLC. SureView®, ThreatSeeker®, Triton®, Sidewinder®, and Stonesoft® are registered trademarks of Forcepoint, LLC. Raytheon® is a registered trademark of Raytheon Company. All other trademarks and registered trademarks are the property of their respective owners.

Copyright © 2000-2020 Forcepoint LLC. All rights reserved.