CVE Vulnerabilities

CVE-2020-6024

Improper Privilege Management

Published: Jan 20, 2021 | Modified: Feb 02, 2021
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all authenticated users.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Smartconsole Checkpoint * r80.10 (including)
Smartconsole Checkpoint r80.20 (including) r80.20 (including)
Smartconsole Checkpoint r80.30 (including) r80.30 (including)
Smartconsole Checkpoint r80.40 (including) r80.40 (including)
Smartconsole Checkpoint r81 (including) r81 (including)

Potential Mitigations

References