2.3

CVE-2022-23744

Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed to disable endpoint protection by a local administrator.

Data is provided by the National Vulnerability Database (NVD)
CheckpointEndpoint Security Versione83
CheckpointEndpoint Security Versione84
CheckpointEndpoint Security Versione85
CheckpointEndpoint Security Versione86.10
CheckpointEndpoint Security Versione86.20
CheckpointEndpoint Security Versione86.30
CheckpointEndpoint Security Versione86.40
CheckpointHarmony Endpoint Versione83
CheckpointHarmony Endpoint Versione84
CheckpointHarmony Endpoint Versione85
CheckpointHarmony Endpoint Versione86.10
CheckpointHarmony Endpoint Versione86.20
CheckpointHarmony Endpoint Versione86.30
CheckpointHarmony Endpoint Versione86.40
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.32
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.3 0.8 1.4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.