# Check Point Response to CVE-2023-28130 - Hostname command injection in Gaia Portal

Please read this important update from Check Point.

Security Alert:

- **Severity:** Medium  
- **Product:** Security Gateways, Security Management  
- **Version:** R80.20 (EOS), R80.20SP (EOS), R80.30SP (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20  
- **OS:** Gaia  
- **Last Modified:** 2025-02-09

## Symptoms

- Local user may lead to privilege escalation using Gaia Portal "Hosts and DNS" page.

This issue received the ID [CVE-2023-28130](https://www.cve.org/CVERecord?id=VE-2023-28130).

## Solution

This problem was fixed. The fix adds more validations on user input and is included starting from:

- [Check Point R82](https://support.checkpoint.com/results/sk/sk181127)  
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 14  
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 95  
- [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 82  
- [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 198
  
## Article Properties

- **Access Level:** General  
- **Severity:** Medium  
- **Status:** Approved  
- **Date Created:** 2023-07-25  
- **Last Modified:** 2025-02-09
