Release notes for update package 1856-5242

This update package improves the detection capabilities of the Forcepoint NGFW system.

RELEASE DATE:    Wednesday March 26, 2025
MD5 CHECKSUM:    714d026edd635b4567deadfc63f74a42
SHA1 CHECKSUM:    80b3a6be3358912fc7f77f8edb335043a129a85b
SHA256 CHECKSUM:    01c458ec8a8ed24c8ab685f926d0bf204b8ae790d39df3531ed98f3c95a7d5a8


UPDATE CRITICALITY:    HIGH

MINIMUM SOFTWARE VERSIONS
- Forcepoint NGFW Security Management Center:    6.10.1.11125
- Forcepoint NGFW:    6.8.1.24103

List of detected attacks in this update package:

Risk levelDescriptionReferenceVulnerability
High     An attempt to exploit a vulnerability in Ingress NGINX Controller for Kubernetes detected     CVE-2025-1097     Ingress-Nginx-Controller-Kubernetes-Annotation-Injection-CVE-2025-1097

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

Text File Stream

RiskVulnerability/SituationReferencesRelated FingerprintSituation Type
High Ingress-Nginx-Controller-Kubernetes-Annotation-Injection-CVE-2025-1097 CVE-2025-1097 File-Text_Ingress-Nginx-Controller-Kubernetes-Annotation-Injection Suspected Compromise

LIST OF OTHER CHANGES:

New objects:

TypeName
Categoryingress-nginx

Updated objects:

TypeNameChanges
IPListTOR exit nodes IP Address List
IPListAmazon AMAZON
IPListAmazon EC2
IPListAmazon CLOUDFRONT
IPListTOR relay nodes IP Address List
IPListAmazon AMAZON af-south-1
IPListAmazon EC2 af-south-1
IPListAmazon AMAZON ap-northeast-1
IPListAmazon EC2 ap-northeast-1
IPListMalicious Site IP Address List
IPListAmazon AMAZON ap-south-1
IPListAmazon EC2 ap-south-1
IPListAmazon AMAZON ap-southeast-1
IPListAmazon EC2 ap-southeast-1
IPListNordVPN Servers IP Address List
IPListAmazon AMAZON ap-southeast-2
IPListAmazon EC2 ap-southeast-2
IPListAmazon AMAZON ca-central-1
IPListAmazon EC2 ca-central-1
IPListAmazon AMAZON eu-central-1
IPListAmazon EC2 eu-central-1
IPListAmazon AMAZON eu-north-1
IPListAmazon EC2 eu-north-1
IPListAmazon AMAZON me-south-1
IPListAmazon EC2 me-south-1
IPListAmazon CLOUDFRONT sa-east-1
IPListAmazon AMAZON us-east-1
IPListAmazon EC2 us-east-1
IPListAmazon AMAZON us-east-2
IPListAmazon EC2 us-east-2
IPListForcepoint Drop IP Address List
IPListAmazon AMAZON us-west-2
IPListAmazon EC2 us-west-2
ApplicationTOR
ApplicationNordVPN

HOW TO IMPORT AND ACTIVATE THE DYNAMIC UPDATE PACKAGE

  1. Download the dynamic update package, then make sure that the checksums for the original files and the files that you have downloaded match.
  2. In the Management Client, select Menu > File > Import > Import Update Packages.
  3. Browse to the file, select it, then click Import.
  4. Select  Configuration, then browse to Administration > Other Elements > Updates.
  5. Right-click the imported dynamic update package, then select Activate.
  6. When the activation is finished, refresh the policy on all NGFW Engines. If your policy uses a custom template, you might need to edit the policy.

DISCLAIMER AND COPYRIGHT

Copyright © 2025 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.