Vulnerabilidades en checkpoint

33 resultados
Análisis Vexday

Checkpoint tem 28 vulnerabilidades catalogadas na base, com 12 publicadas nos últimos 90 dias e 3 já sob ataque ativo. A fraqueza predominante é exposição de informações sensíveis (CWE-200), apesar de apenas 3 vulnerabilidades críticas, indicando risco moderado mas com exploração confirmada em operações.

CVE-2024-24919HIGHInformation disclosureEPSS 100.0%KEVCVE-2026-50751CRITICALUser Authentication Bypass in VPN Remote Access and Mobile AccessEPSS 83.8%KEVCVE-2026-16232CRITICALAuthentication Bypass in the SmartConsole Login Process Using an Application TokenEPSS 72.1%KEVCVE-2026-62144CRITICALManagement Authentication Bypass and Privilege EscalationEPSS 20.8%CVE-2026-62145HIGHLocal Privilege Escalation in Gaia PortalEPSS 7.6%CVE-2026-50752HIGHCertificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1EPSS 5.0%CVE-2026-48133HIGHIdentity Awareness Captive Portal - Unauthenticated Local File InclusionEPSS 4.8%CVE-2026-48134MEDIUMSQL injection issue in UserCheck Portal when DLP Software Blade is activeEPSS 4.4%CVE-2026-48136MEDIUMAuthenticated Administrator Role-Based Access Control Bypass in ComplianceEPSS 4.1%CVE-2024-24916MEDIUMDLL-HiJackingEPSS 2.7%CVE-2026-48131HIGHVPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number ZeroEPSS 2.7%CVE-2026-48135MEDIUMHTTP service can incorrectly process malformed HTTP requestsEPSS 2.6%CVE-2026-93616CRITICALDirectory Traversal and File upload allows execution of arbitrary script on the Management ServerEPSS 2.4%KEVCVE-2026-48132HIGHVPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDPEPSS 2.1%CVE-2026-18574CRITICALAuthentication Bypass in Check Point Security Management ServerEPSS 1.0%CVE-2026-85102CRITICALImproper Certificate Validation in Quantum Security GatewayEPSS 0.7%KEVCVE-2026-91843CRITICALStack overflow in login process to the Security Management and Log ServersEPSS 0.5%CVE-2024-52885MEDIUMPath TraversalEPSS 0.5%CVE-2024-24914HIGHAuthenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vEPSS 0.4%CVE-2024-24911MEDIUMOut of Bounds read in the CPCA process on Check Point Management ServerEPSS 0.4%