Impact
An authentication bypass flaw in Check Point’s Security Management and Multi‑Domain Security Management lets an unauthenticated attacker run administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a misconfigured Trusted Client list.
Affected Systems
Check Point Multi‑Domain Security Management and Quantum Security Management are affected. No specific version information is provided in the advisory, so all instances of these products are considered at risk until patched.
Risk and Exploitability
The CVSS score of 9.1 indicates critical severity and the attack vector is remote over a network. Exploitation requires that the attacker can reach the Management Server without firewall protection or with a misconfigured Trusted Client list. The EPSS score of 21% indicates a high probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, but the lack of protective controls can still render the system highly susceptible. If exposed to the public internet or an untrusted network, the exploit can be readily performed, resulting in administrative control.
OpenCVE Enrichment