sk181311 - Check Point Response to CVE-2023-28130 - Hostname command injection in Gaia Portal
Check Point Response to CVE-2023-28130 - Hostname command injection in Gaia Portal
Please read this important update from Check Point.
Security Alert:
- Severity: Medium
- Product: Security Gateways, Security Management
- Version: R80.20 (EOS), R80.20SP (EOS), R80.30SP (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
- OS: Gaia
- Last Modified: 2025-02-09
Symptoms
- Local user may lead to privilege escalation using Gaia Portal "Hosts and DNS" page.
This issue received the ID CVE-2023-28130.
Solution
This problem was fixed. The fix adds more validations on user input and is included starting from:
- Check Point R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 14
- Jumbo Hotfix Accumulator for R81.10 starting from Take 95
- Jumbo Hotfix Accumulator for R81 starting from Take 82
- Jumbo Hotfix Accumulator for R80.40 starting from Take 198
Article Properties
- Access Level: General
- Severity: Medium
- Status: Approved
- Date Created: 2023-07-25
- Last Modified: 2025-02-09