8

CVE-2024-24914

Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CheckpointGaia Os Versionr81
   CheckpointClusterxl Version-
   CheckpointMulti-domain Management Version-
   CheckpointQuantum 6700 Version-
   CheckpointQuantum Maestro Version-
   CheckpointQuantum Scalable Chassis Version-
   CheckpointQuantum Security Gateway Version-
   CheckpointQuantum Security Management Version-
   CheckpointQuantum Spark Version-
CheckpointGaia Os Versionr81.10
   CheckpointClusterxl Version-
   CheckpointMulti-domain Management Version-
   CheckpointQuantum 6700 Version-
   CheckpointQuantum Maestro Version-
   CheckpointQuantum Scalable Chassis Version-
   CheckpointQuantum Security Gateway Version-
   CheckpointQuantum Security Management Version-
   CheckpointQuantum Spark Version-
CheckpointGaia Os Versionr81.20
   CheckpointClusterxl Version-
   CheckpointMulti-domain Management Version-
   CheckpointQuantum 6700 Version-
   CheckpointQuantum Maestro Version-
   CheckpointQuantum Scalable Chassis Version-
   CheckpointQuantum Security Gateway Version-
   CheckpointQuantum Security Management Version-
   CheckpointQuantum Spark Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.437
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cve@checkpoint.com 8 2.1 5.9
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-914 Improper Control of Dynamically-Identified Variables

The product does not properly restrict reading from or writing to dynamically-identified variables.