Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCheckpoint Clusterxl
HWCheckpointall versionsCheckpoint Gaia Os
OSCheckpointr81r81.10r81.20Checkpoint Multi Domain Management
HWCheckpointall versionsCheckpoint Quantum 6700
HWCheckpointall versionsCheckpoint Quantum Maestro
HWCheckpointall versionsCheckpoint Quantum Scalable Chassis
HWCheckpointall versionsCheckpoint Quantum Security Gateway
HWCheckpointall versionsCheckpoint Quantum Security Management
HWCheckpointall versionsCheckpoint Quantum Spark
HWCheckpointall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2026-16232CRITICAL9.3⚠ KEVPL ✓same product
Authentication bypass w Check Point SmartConsole — pełny dostęp administratora
CVE-2026-50751CRITICAL9.3⚠ KEVPL ✓same product
Auth Bypass w Check Point VPN — pominięcie uwierzytelnienia przez błąd IKEv1
CVE-2024-24919HIGH8.6⚠ KEVsame product
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected t...
CVE-2024-52885MEDIUM5.0same product
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an a...
CVE-2024-52888MEDIUM5.4same product
For an authenticated end-user the portal may run a script while attempting to display a directory or some file...