Directory Traversal and File upload allows execution of arbitrary script on the Management Server
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
An attacker can bypass security checks to upload and run harmful scripts on Check Point's management server without needing a password. This is critical because the management server controls all security policies.
Unauthenticated directory traversal combined with arbitrary file upload enables remote code execution on the Management Server. The vulnerability allows attackers to traverse directory restrictions and upload malicious scripts that execute with server privileges, bypassing authentication requirements entirely.