CVE-2023-28130
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
26/07/2023
Last modified:
23/08/2024
Description
Local user may lead to privilege escalation using Gaia Portal hostnames page.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:checkpoint:gaia_portal:r80.40:-:*:*:*:*:*:* | ||
| cpe:2.3:a:checkpoint:gaia_portal:r81:-:*:*:*:*:*:* | ||
| cpe:2.3:a:checkpoint:gaia_portal:r81.10:-:*:*:*:*:*:* | ||
| cpe:2.3:a:checkpoint:gaia_portal:r81.20:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/173918/Checkpoint-Gaia-Portal-R81.10-Remote-Command-Execution.html
- http://seclists.org/fulldisclosure/2023/Aug/4
- http://seclists.org/fulldisclosure/2023/Jul/43
- https://pentests.nl/pentest-blog/cve-2023-28130-command-injection-in-check-point-gaia-portal/
- https://support.checkpoint.com/results/sk/sk181311


