7.2

CVE-2024-24915

SmartConsole Sensitive Credential Exposure via Memory Dump

Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Checkpoint ≫ Smartconsole Version r81.10 Update build400
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build402
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build404
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build406
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build407
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build409
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build410
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build412
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build413
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build414
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build416
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build417
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build418
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build420
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build423
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build424
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build425
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build426
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build427
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build428
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.10 Update build429
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build640
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build641
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build645
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build646
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build649
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build651
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build653
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build654
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build655
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build656
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build658
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build659
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build660
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build661
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r81.20 Update build663
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r82 Update build1051
   Microsoft ≫ Windows Version -
Checkpoint ≫ Smartconsole Version r82 Update build1053
   Microsoft ≫ Windows Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.071
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Checkpoint 6.1 0.2 5.9
CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

CWE-316 Cleartext Storage of Sensitive Information in Memory

The product stores sensitive information in cleartext in memory.

https://support.checkpoint.com/results/sk/sk183545
Vendor Advisory