Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m2xx-23gx-734v

Опубликовано: 22 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

EPSS

Процентиль: 96%
0.12685
Средний

9.1 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.1
nvd
8 дней назад

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

CVSS3: 9.1
fstec
9 дней назад

Уязвимость приложения для управления системами безопасности Check Point SmartConsole, связанная с недостатками процедуры аутентификации, позволяющая нарушителю обойти существующие механизмы безопасности и выполнить произвольный код

EPSS

Процентиль: 96%
0.12685
Средний

9.1 Critical

CVSS3

Дефекты

CWE-287