Описание
Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all authenticated users.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до r80.10 (включая)
Одно из
cpe:2.3:a:checkpoint:smartconsole:*:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:smartconsole:r80.20:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:smartconsole:r80.30:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:smartconsole:r80.40:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:smartconsole:r81:*:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00044
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-114
CWE-269
Связанные уязвимости
github
больше 3 лет назад
Check Point SmartConsole before R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all authenticated users.
EPSS
Процентиль: 13%
0.00044
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-114
CWE-269