Impact
Based on the limited description, it is inferred that the flaw lies in the HTTP service's handling of malformed requests. The parsing logic fails to validate the request format properly, potentially leading to service disruption and denial of service. The vulnerability does not provide a direct path to remote code execution.
Affected Systems
All Check Point Quantum Security Gateway devices that use the affected HTTP service, regardless of model or firmware, are potentially impacted. No specific software versions were disclosed, so any deployed instance may be vulnerable.
Risk and Exploitability
With a CVSS score of 5.3 the issue is considered of moderate severity. The EPSS score is 2.61%, and it is not catalogued in the CISA KEV list, indicating a lower probability of widespread exploitation. The likely attack vector is remote, accessible to any network entity that can send HTTP traffic to the gateway. An attacker could trigger the vulnerability by sending specially crafted requests over the network, potentially causing service interruption.
OpenCVE Enrichment