CVE-2020-6020

Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38, can be manipulated to run commands as a high privileged user or crash, due to weak input validation on inputs by a trusted management administrator.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:checkpoint:ica_management_portal:*:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:ica_management_portal:r80.20:-:*:*:*:*:*:*
cpe:2.3:a:checkpoint:ica_management_portal:r80.20:take_156:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:checkpoint:ica_management_portal:*:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:ica_management_portal:r80.30:-:*:*:*:*:*:*
cpe:2.3:a:checkpoint:ica_management_portal:r80.30:take_200:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:checkpoint:ica_management_portal:*:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:ica_management_portal:r80.40:-:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:checkpoint:ica_management_portal:*:*:*:*:*:*:*:*
cpe:2.3:a:checkpoint:ica_management_portal:r80.10:-:*:*:*:*:*:*

History

21 Nov 2024, 05:34

Type Values Removed Values Added
References () https://supportcontent.checkpoint.com/solutions?id=sk142952 - Vendor Advisory () https://supportcontent.checkpoint.com/solutions?id=sk142952 - Vendor Advisory

Information

Published : 2020-09-24 14:15

Updated : 2024-11-21 05:34


NVD link : CVE-2020-6020

Mitre link : CVE-2020-6020

CVE.ORG link : CVE-2020-6020


JSON object : View

Products Affected

checkpoint

  • ica_management_portal
CWE
CWE-20

Improper Input Validation