7.2

CVE-2024-24915

Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
CheckpointSmartconsole Versionr81.10 Updatebuild400
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild402
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild404
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild406
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild407
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild409
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild410
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild412
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild413
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild414
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild416
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild417
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild418
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild420
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild423
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild424
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild425
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild426
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild427
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild428
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.10 Updatebuild429
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild640
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild641
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild645
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild646
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild649
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild651
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild653
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild654
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild655
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild656
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild658
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild659
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild660
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild661
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr81.20 Updatebuild663
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr82 Updatebuild1051
   MicrosoftWindows Version-
CheckpointSmartconsole Versionr82 Updatebuild1053
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.029
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cve@checkpoint.com 6.1 0.2 5.9
CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

CWE-316 Cleartext Storage of Sensitive Information in Memory

The product stores sensitive information in cleartext in memory.