PT-2023-4187 · Check Point · Check Point Gaia Portal+1

Danny De Weille

+1

·

Published

2023-03-08

·

Updated

2024-08-23

·

CVE-2023-28130

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Check Point Gaia Portal (affected versions not specified)
Description The issue is related to a command injection vulnerability in the Check Point Gaia Portal. It allows a local user to potentially escalate privileges using the Gaia Portal hostnames page. The vulnerability is due to the failure to neutralize special elements used in the operating system command when processing the hostname parameter. This could enable a remote attacker to execute arbitrary commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04502
CVE-2023-28130

Affected Products

Check Point Gaia
Check Point Gaia Portal