« Volver al listado

CVE-2024-52887

Estado: AnalizadaMedia (5.4)—

Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-52887",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-52887",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-28T15:49:03.217887Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@checkpoint.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.5,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "cve@checkpoint.com",
      "affectedData": [
        {
          "vendor": "checkpoint",
          "product": "Check Point Mobile Access",
          "versions": [
            {
              "status": "affected",
              "version": "Check Point Mobile Access versions R81.10, R81.20, R82"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-04-27T08:15:14.077",
  "references": [
    {
      "url": "https://support.checkpoint.com/results/sk/sk183054",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@checkpoint.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@checkpoint.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list."
    },
    {
      "lang": "es",
      "value": "El usuario final autenticado puede configurar un marcador SNX especialmente manipulado que puede hacer que su navegador ejecute un script mientras accede a su propia lista de marcadores."
    }
  ],
  "lastModified": "2026-06-17T08:07:48.677",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:checkpoint:mobile_access:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "615942BD-BD17-41D7-8581-F5B7C7937BD5"
            },
            {
              "criteria": "cpe:2.3:a:checkpoint:remote_access_vpn:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CE7D305-2FF3-4003-8127-C2DB68E06AC8"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:checkpoint:gaia_os:r81.10:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "55864700-51C8-4540-B4B2-05CE4C7FC245"
            },
            {
              "criteria": "cpe:2.3:o:checkpoint:gaia_os:r81.20:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3BE80E1E-02E1-44E3-B309-3079F0F5A89C"
            },
            {
              "criteria": "cpe:2.3:o:checkpoint:gaia_os:r82:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6443AE50-1CB5-4D00-8C8D-97DB966687DD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@checkpoint.com"
}