Vulnerability Details CVE-2024-24914
Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.1%
CVSS Severity
CVSS v3 Score 8.0
Products affected by CVE-2024-24914
-
cpe:2.3:h:checkpoint:clusterxl:-
-
cpe:2.3:h:checkpoint:multi-domain_management:-
-
cpe:2.3:h:checkpoint:quantum_6700:-
-
cpe:2.3:h:checkpoint:quantum_maestro:-
-
cpe:2.3:h:checkpoint:quantum_scalable_chassis:-
-
cpe:2.3:h:checkpoint:quantum_security_gateway:-
-
cpe:2.3:h:checkpoint:quantum_security_management:-
-
cpe:2.3:h:checkpoint:quantum_spark:-
-
cpe:2.3:o:checkpoint:gaia_os:r81
-
cpe:2.3:o:checkpoint:gaia_os:r81.10
-
cpe:2.3:o:checkpoint:gaia_os:r81.20