Impact
An authentication bypass flaw (CWE‑288) allows an unauthenticated remote attacker with network access to the Management services to execute arbitrary system commands on the Check Point Security Management Server. Successful exploitation can lead to a full compromise of the security management system, effectively giving the attacker unlimited administrative control without proper authentication.
Affected Systems
The vulnerability affects Check Point Multi‑Domain Security Management Server and Check Point Security Management Server. No specific version information is provided in the CVE data.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. The attack requires network connectivity to the Management services, implying a network‑based vector. Once authenticated bypass is achieved, arbitrary commands can be run with the privileges of the Security Management Server process.
OpenCVE Enrichment