Directory Access Vulnerability in Check Point Security Management Portal
CVE-2024-52888
5.4MEDIUM
Summary
An authenticated user of the Check Point Security Management Portal may encounter a flaw where scripts can be executed while the portal tries to display directory listings or file properties. This vulnerability might expose the system to unnecessary risks, enabling potential unauthorized actions under specific conditions. Users are encouraged to review their security practices and ensure they are operating on updated versions to mitigate this issue.
Affected Version(s)
Check Point Mobile Access Check Point Mobile Access versions R81.10, R81.20, R82
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved