Impact
A flaw in the Check Point Gaia Portal allows an authenticated user with only read‑only portal privileges to execute arbitrary system commands as root. The weakness is a privilege‑escalation issue (CWE‑269) and would grant an attacker full control over the gateway, enabling changes to firewall policies, installation of malware, and total compromise of the device’s protective functions.
Affected Systems
The affected products are the Check Point Quantum Security Gateway and the Check Point Quantum Security Management systems that provide the Gaia Portal. Exact firmware or release versions affected were not disclosed in the CVE data, so the vulnerability could be present in any Gaia Portal deployment until a patch or newer firmware is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates a high risk to confidentiality, integrity, and availability, and the EPSS score of 8% suggests a moderate likelihood that this vulnerability will be actively exploited. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attacker must first authenticate to the Gaia Portal with a read‑only account; once logged in, no additional conditions are required for privilege escalation.
OpenCVE Enrichment