« Volver al listado

CVE-2020-6020

Estado: ModificadaMedia (6.4)—

Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38, can be manipulated to run commands as a high privileged user or crash, due to weak input validation on inputs by a trusted management administrator.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-6020",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.4,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:S/C:C/I:C/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 9.5,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 5.1,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.4,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@checkpoint.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "ICA Management Portal",
          "versions": [
            {
              "status": "affected",
              "version": "before JHFs R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-09-24T14:15:13.743",
  "references": [
    {
      "url": "https://supportcontent.checkpoint.com/solutions?id=sk142952",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@checkpoint.com"
    },
    {
      "url": "https://supportcontent.checkpoint.com/solutions?id=sk142952",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@checkpoint.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38, can be manipulated to run commands as a high privileged user or crash, due to weak input validation on inputs by a trusted management administrator."
    },
    {
      "lang": "es",
      "value": "Una administración web de Internal CA de Check Point Security Management anterior a HFA Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38, puede ser manipulada para ejecutar comandos como un usuario muy privilegiado o un bloqueo, debido a una comprobación débil de la entrada por parte de un administrador de gestión confiable"
    }
  ],
  "lastModified": "2026-06-17T03:22:36.153",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:checkpoint:ica_management_portal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B5CD4D5-FE12-47A4-B488-C5C79192C1FC",
              "versionEndExcluding": "r80.20"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:ica_management_portal:r80.20:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD6BFA69-7391-4D84-9355-B62C682FA5A3"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:ica_management_portal:r80.20:take_156:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90E4E78D-86F7-45ED-A433-98471057D812"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:checkpoint:ica_management_portal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F76C3DB-4DB8-48C4-82F1-2C76DA050F79",
              "versionEndExcluding": "r80.30"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:ica_management_portal:r80.30:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "84C8736D-E8EE-415D-A144-70EDE2DC1AB3"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:ica_management_portal:r80.30:take_200:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "760B689F-AC28-4A08-AFD6-7C686D997F22"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:checkpoint:ica_management_portal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89F23E66-6FE4-47F7-8D82-139D7A2E5781",
              "versionEndExcluding": "r80.40"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:ica_management_portal:r80.40:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39C0C737-1472-41A1-903E-285D3CBBB7DA"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:checkpoint:ica_management_portal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5AF5484-895A-4FF3-BD43-65CCF7F1C419",
              "versionEndExcluding": "r80.10"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:ica_management_portal:r80.10:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "129933AF-E0EC-4766-B2E0-596EE9D60FF9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@checkpoint.com"
}