Release notes for update package 1911-5242

This update package improves the detection capabilities of the Forcepoint LLM system.

RELEASE DATE:     Monday August 11, 2025
MD5 CHECKSUM:     b3b8dded30672f846d477266860e9297
SHA1 CHECKSUM:     b2667b86a4e769837c02b73283b6aa676b647619
SHA256 CHECKSUM:     c6453395dc040dfc7444c6187c09c7b6be973bfc7ea4acee57431e72811a11f4


UPDATE CRITICALITY:    HIGH

List of detected attacks in this update package:

Risk level Description Reference Vulnerability
High     An attempt to exploit a vulnerability in Cisco Systems ISE     CVE-2025-20337     Cisco-ISE-EnableStrongSwanTunnel-Insecure-Deserialization-CVE-2025-20337
High     An attempt to exploit a vulnerability in SQLite     CVE-2025-6965     Sqlite-FindOrCreateAggInfoColumn-Integer-Truncation-CVE-2025-6965
High     An attempt to exploit a vulnerability in ICTBroadcast     CVE-2025-2611     ICTBroadcast-Unauthenticated-Remote-Code-Execution
High     An attempt to exploit a vulnerability in PAN-OS GlobalProtect detected     CVE-2025-0133     PAN-OS-GlobalProtect-Reflected-Cross-Site-Scripting-CVE-2025-0133

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

HTTP Request URI

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High PAN-OS-GlobalProtect-Reflected-Cross-Site-Scripting-CVE-2025-0133 CVE-2025-0133 HTTP_CSU-PAN-OS-GlobalProtect-Reflected-Cross-Site-Scripting-CVE-2025-0133 Suspected Compromise

HTTP Request Header Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High ICTBroadcast-Unauthenticated-Remote-Code-Execution CVE-2025-2611 HTTP_CSH-ICTBroadcast-Unauthenticated-Remote-Code-Execution Suspected Compromise

HTTP Normalized Request-Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Cisco-ISE-EnableStrongSwanTunnel-Insecure-Deserialization-CVE-2025-20337 CVE-2025-20337 HTTP_CRL-Cisco-Identity-Services-Engine-EnableStrongSwanTunnel-Insecure-Deserialization-CVE-2025-20337 Suspected Compromise

Text File Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Sqlite-FindOrCreateAggInfoColumn-Integer-Truncation-CVE-2025-6965 CVE-2025-6965 File-Text_Sqlite-FindOrCreateAggInfoColumn-Integer-Truncation-CVE-2025-6965 Suspected Compromise

Updated detected attacks:

HTTP Request Header Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High Microsoft-Sharepoint-Improper-Authentication-CVE-2025-49706 CVE-2025-49706 HTTP_CSH-Microsoft-Sharepoint-Improper-Authentication-CVE-2025-49706 Suspected Compromise
Description has changed

HTTP Normalized Request-Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High HTTP-Possible-Cross-Site-Scripting No CVE/CAN HTTP_CRL-Possible-Cross-Site-Scripting-Attempt Potential Compromise
Fingerprint regexp changed

LIST OF OTHER CHANGES:

New objects:

Type Name
Category ICTBroadcast
Category SQLite
IPList Amazon API_GATEWAY ap-southeast-6

Updated objects:

Type Name Changes
IPList TOR exit nodes IP Address List
IPList Amazon AMAZON
IPList Amazon EC2
IPList TOR relay nodes IP Address List
IPList Zscaler IP Address List
IPList Botnet IP Address List
IPList Malicious Site IP Address List
IPList NordVPN Servers IP Address List
IPList Amazon EC2 sa-west-1
IPList Amazon AMAZON sa-west-1
IPList Amazon AMAZON sa-east-1
IPList Amazon EC2 sa-east-1
IPList Amazon AMAZON us-east-1
IPList Amazon EC2 us-east-1
IPList Forcepoint Drop IP Address List
Situation HTTP_CSH-Proxy-Header
Fingerprint regexp changed
Application TOR
Application NordVPN

DISCLAIMER AND COPYRIGHT

Copyright © 2025 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.