7.2

CVE-2024-24915

SmartConsole Sensitive Credential Exposure via Memory Dump

Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CheckpointSmartconsole Versionr81.10 Updatebuild400
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild402
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild404
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild406
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild407
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild409
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild410
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild412
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild413
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild414
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild416
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild417
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild418
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild420
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild423
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild424
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild425
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild426
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild427
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild428
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild429
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild640
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild641
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild645
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild646
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild649
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild651
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild653
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild654
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild655
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild656
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild658
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild659
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild660
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild661
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild663
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr82 Updatebuild1051
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr82 Updatebuild1053
   MicrosoftWindows Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.343
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cve@checkpoint.com 6.1 0.2 5.9
CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

CWE-316 Cleartext Storage of Sensitive Information in Memory

The product stores sensitive information in cleartext in memory.