CVE-2023-28130
high · 7.2Local user may lead to privilege escalation using Gaia Portal hostnames page.
7.2
CVSS
20.9%
EPSS (exploit prob.)
97th
EPSS percentile
2023-07-26
Published
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-20CWE-77
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| checkpoint | gaia_portal | r80.40 |
| checkpoint | gaia_portal | r81 |
| checkpoint | gaia_portal | r81.10 |
| checkpoint | gaia_portal | r81.20 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/173918/Checkpoint-Gaia-Portal-R81.10-Remote-Command-Execution.html
- http://seclists.org/fulldisclosure/2023/Aug/4
- http://seclists.org/fulldisclosure/2023/Jul/43
- https://pentests.nl/pentest-blog/cve-2023-28130-command-injection-in-check-point-gaia-portal/
- https://support.checkpoint.com/results/sk/sk181311
- http://packetstormsecurity.com/files/173918/Checkpoint-Gaia-Portal-R81.10-Remote-Command-Execution.html
- http://seclists.org/fulldisclosure/2023/Aug/4
- http://seclists.org/fulldisclosure/2023/Jul/43
- https://pentests.nl/pentest-blog/cve-2023-28130-command-injection-in-check-point-gaia-portal/
- https://support.checkpoint.com/results/sk/sk181311
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-28130