Authentication Bypass in the SmartConsole Login Process Using an Application Token
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
An unauthenticated attacker can bypass the login process in Check Point SmartConsole and obtain an administrative token, allowing full control over security policies without needing valid credentials.
CWE-287 authentication bypass in SmartConsole's login process allows remote unauthenticated attackers to directly obtain application tokens with administrative privileges. Exploitation requires network access to the Management Server IP and requires that Trusted Clients restrictions are not configured; successful exploitation grants full modification rights to security policies and configurations.