CVE-2020-6020

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
24/09/2020
Last modified:
16/11/2022

Description

Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38, can be manipulated to run commands as a high privileged user or crash, due to weak input validation on inputs by a trusted management administrator.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:checkpoint:ica_management_portal:*:*:*:*:*:*:*:* r80.20 (excluding)
cpe:2.3:a:checkpoint:ica_management_portal:r80.20:-:*:*:*:*:*:*
cpe:2.3:a:checkpoint:ica_management_portal:r80.20:take_156:*:*:*:*:*:*
cpe:2.3:a:checkpoint:ica_management_portal:*:*:*:*:*:*:*:* r80.30 (excluding)
cpe:2.3:a:checkpoint:ica_management_portal:r80.30:-:*:*:*:*:*:*
cpe:2.3:a:checkpoint:ica_management_portal:r80.30:take_200:*:*:*:*:*:*
cpe:2.3:a:checkpoint:ica_management_portal:*:*:*:*:*:*:*:* r80.40 (excluding)
cpe:2.3:a:checkpoint:ica_management_portal:r80.40:-:*:*:*:*:*:*
cpe:2.3:a:checkpoint:ica_management_portal:*:*:*:*:*:*:*:* r80.10 (excluding)
cpe:2.3:a:checkpoint:ica_management_portal:r80.10:-:*:*:*:*:*:*


References to Advisories, Solutions, and Tools