Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-10493

Опубликовано: 22 июл. 2026
Источник: fstec
CVSS3: 9.1
CVSS2: 9.4
EPSS Средний

Описание

Уязвимость приложения для управления системами безопасности Check Point SmartConsole связана с недостатками процедуры аутентификации. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, обойти существующие механизмы безопасности и выполнить произвольный код

Вендор

Check Point Software Technologies Ltd.

Наименование ПО

Security Management Server
Multi-Domain Security Management Server (MDS)
Check Point SmartConsole

Версия ПО

до R81.20 (Security Management Server)
до R81.20 (Multi-Domain Security Management Server (MDS))
до R82 (Multi-Domain Security Management Server (MDS))
до R82.10 (Multi-Domain Security Management Server (MDS))
до R82.10 (Security Management Server)
до R82 (Security Management Server)
- (Check Point SmartConsole)

Тип ПО

ПО сетевого программно-аппаратного средства
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 9,4)
Критический уровень опасности (базовая оценка CVSS 3.1 составляет 9,1)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://support.checkpoint.com/results/sk/sk185169/

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 96%
0.12685
Средний

9.1 Critical

CVSS3

9.4 Critical

CVSS2

Связанные уязвимости

CVSS3: 9.1
nvd
8 дней назад

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

CVSS3: 9.1
github
8 дней назад

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

EPSS

Процентиль: 96%
0.12685
Средний

9.1 Critical

CVSS3

9.4 Critical

CVSS2