HIGH🇵🇱 Wersja polska

CVE-2024-24914

CVSS 8.0v3.1pub. 2024-11-07upd. 2025-08-26

Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Checkpoint Clusterxl

    HW
    Checkpoint
    all versions
  • Checkpoint Gaia Os

    OS
    Checkpoint
    r81r81.10r81.20
  • Checkpoint Multi Domain Management

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum 6700

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Maestro

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Scalable Chassis

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Security Gateway

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Security Management

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark

    HW
    Checkpoint
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-16232CRITICAL9.3⚠ KEVPL ✓same product

Authentication bypass w Check Point SmartConsole — pełny dostęp administratora

CVE-2026-50751CRITICAL9.3⚠ KEVPL ✓same product

Auth Bypass w Check Point VPN — pominięcie uwierzytelnienia przez błąd IKEv1

CVE-2024-24919HIGH8.6⚠ KEVsame product

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected t...

CVE-2024-52885MEDIUM5.0same product

The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an a...

CVE-2024-52888MEDIUM5.4same product

For an authenticated end-user the portal may run a script while attempting to display a directory or some file...