« Volver al listado

CVE-2020-6024

Estado: ModificadaAlta (7.8)—

Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all authenticated users.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-6024",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@checkpoint.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Check Point SmartConsole",
          "versions": [
            {
              "status": "affected",
              "version": "R80.20, R80.30, R80.40, R81"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-01-20T19:15:12.947",
  "references": [
    {
      "url": "https://supportcontent.checkpoint.com/solutions?id=sk142952",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@checkpoint.com"
    },
    {
      "url": "https://supportcontent.checkpoint.com/solutions?id=sk142952",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@checkpoint.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-114"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all authenticated users."
    },
    {
      "lang": "es",
      "value": "Check Point SmartConsole versión anterior a R80.10 Build 185, versión R80.20 Build 119, versión R80.30 anterior a Build 94, versión R80.40 anterior a Build 415 y la versión R81 anterior a Build 548 eran vulnerables a una posible escalada de privilegios local debido a la ejecución de ejecutables desde un directorio con acceso de escritura para todos los usuarios autenticados"
    }
  ],
  "lastModified": "2026-06-17T03:22:36.570",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:checkpoint:smartconsole:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1DD7269-40DD-4A4B-BF0B-E928201BA31D",
              "versionEndIncluding": "r80.10"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:smartconsole:r80.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5DDE7A64-BC36-4C95-BBE4-9BF146AC66DE"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:smartconsole:r80.30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "476C415F-F9E3-4A92-9CCF-13FDA0FA99CF"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:smartconsole:r80.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0AD4456C-5CD1-4615-9658-95CD94B7B603"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:smartconsole:r81:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "613920F7-2800-4B77-8A54-6C6BC6E0D233"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@checkpoint.com"
}