CVE-2024-24914

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/11/2024
Last modified:
26/08/2025

Description

Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:checkpoint:gaia_os:r81:*:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.10:*:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:clusterxl:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:multi-domain_management:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_6700:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_maestro:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_scalable_chassis:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_security_gateway:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_security_management:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools