Lucene search

K
nvd[email protected]NVD:CVE-2021-30361
HistoryMay 11, 2022 - 5:15 p.m.

CVE-2021-30361

2022-05-1117:15:08
CWE-78
web.nvd.nist.gov
3
check point gaia
gui clients
command injection
authentication
administrators
gaia os

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

13.1%

The Check Point Gaia Portal’s GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS.

Affected configurations

Nvd
Node
checkpointgaia_portalRange<2022-04-13
Node
checkpointquantum_security_managementMatch-
AND
checkpointgaia_osMatch-
Node
checkpointquantum_security_gatewayMatch-
AND
checkpointgaia_osMatch-
VendorProductVersionCPE
checkpointgaia_portal*cpe:2.3:a:checkpoint:gaia_portal:*:*:*:*:*:*:*:*
checkpointquantum_security_management-cpe:2.3:h:checkpoint:quantum_security_management:-:*:*:*:*:*:*:*
checkpointgaia_os-cpe:2.3:o:checkpoint:gaia_os:-:*:*:*:*:*:*:*
checkpointquantum_security_gateway-cpe:2.3:h:checkpoint:quantum_security_gateway:-:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

13.1%

Related for NVD:CVE-2021-30361