HIGH🇵🇱 Wersja polska

CVE-2023-28130

CVSS 7.2v3.1pub. 2023-07-26upd. 2024-11-21

Local user may lead to privilege escalation using Gaia Portal hostnames page.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Checkpoint Gaia Portal

    APP
    Checkpoint
    r80.40r81r81.10r81.20
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2021-30361MEDIUM6.7same product

The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Cli...

CVE-2026-16232CRITICAL9.3⚠ KEVPL ✓same vendor

Authentication bypass w Check Point SmartConsole — pełny dostęp administratora

CVE-2026-50751CRITICAL9.3⚠ KEVPL ✓same vendor

Auth Bypass w Check Point VPN — pominięcie uwierzytelnienia przez błąd IKEv1

CVE-2019-8459CRITICAL9.8PL ✓same vendor

Check Point Endpoint Security Client – privilege escalation przez niecytowaną ścieżkę (Unquoted Service Path)

CVE-2024-24919HIGH8.6⚠ KEVsame vendor

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected t...