Impact
An unauthenticated remote attacker can exploit the Check Point SmartConsole login process to obtain an application login token and then use that token to authenticate with full administrative privileges. This allows the attacker to modify security policies and configurations, effectively taking complete control of the management environment. The vulnerability is classified under CWE-287 and achieves a CVSS score of 9.3, indicating a high likelihood of severe impact if exploited.
Affected Systems
The vulnerability affects Check Point products from the Multi‑Domain Security Management and Quantum Security Management lines. No specific version numbers are provided in this advisory.
Risk and Exploitability
The CVSS score of 9.3 places the flaw in the high‑severity range. The EPSS score of 73% indicates a high exploitation probability. The vulnerability is listed in the CISA KEV catalog and has been observed in a very small number of customer environments, implying that exploitation is active. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Based on the description, it is inferred that the attack vector is a remote component‑level exploit against the SmartConsole login API.
OpenCVE Enrichment