PT-2023-4187 · Check Point · Check Point Gaia Portal+1
Danny De Weille
+1
·
Published
2023-03-08
·
Updated
2024-08-23
·
CVE-2023-28130
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Check Point Gaia Portal (affected versions not specified)
Description
The issue is related to a command injection vulnerability in the Check Point Gaia Portal. It allows a local user to potentially escalate privileges using the Gaia Portal hostnames page. The vulnerability is due to the failure to neutralize special elements used in the operating system command when processing the
hostname parameter. This could enable a remote attacker to execute arbitrary commands.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Code Injection
RCE
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Check Point Gaia
Check Point Gaia Portal