Impact
This vulnerability is a stack overflow that occurs during the unauthenticated login phase of Checkpoint's Quantum Security Management and Log Servers. Exploitation allows a remote attacker to execute arbitrary code with root privileges. The flaw is a stack‑based buffer overflow (CWE‑121).
Affected Systems
Checkpoint Quantum Security Management servers that handle security policy management and log data are affected. No specific version range is listed in the CVE; any system that uses the vulnerable login process may be exposed.
Risk and Exploitability
The CVSS score of 9.8 signifies critical impact, while the EPSS score of < 1% suggests that observed exploitation activity is currently minimal. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed public exploitation. Based on the description, the flaw occurs during the unauthenticated login process, so the likely attack vector is remote over the network via malicious authentication data sent to the login endpoint; this could trigger the stack overflow and allow arbitrary code execution with root privileges. Given the severity, organizations should treat the exposure as a high‑priority risk.
OpenCVE Enrichment