VulnerabilityModified
CVE-2021-30361
The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS.
MEDIUM 6.7EPSS 4.47%
Does this matter?
Lower severity and a low EPSS score (4.47%). Track it; it rarely justifies an emergency change on its own.
Description
The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.47% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- checkpoint/gaia portal · checkpoint/gaia os
- Source
- cve@checkpoint.com
References
- https://supportcontent.checkpoint.com/solutions?id=sk179128Patch, Vendor Advisory
- https://supportcontent.checkpoint.com/solutions?id=sk179128Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.