sk182743 - Check Point Response to CVE-2024-24914 - TCL substitution of global parameter values

Check Point Response to CVE-2024-24914 - TCL substitution of global parameter values

Please read this important update from Check Point.

Security Alert:

Medium

Product

Check Point Appliances, ClusterXL, Maestro HyperScale Firewall, Multi-Domain Security Management, Scalable Chassis, Security Gateways, Security Management

Version

R81 (EOS), R81.10 (EOS), R81.20

OS

Gaia

Last Modified

2025-02-09

Symptoms

This issue received the ID CVE-2024-24914.

Solution

This problem was fixed.

The solution adds a defense mechanism in Gaia Portal against code injections that use special HTTP requests.

The fix is included starting from:

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

Revision History

Date Description
21 Nov 2024 Added the "Revision History" section
19 Nov 2024 - In the "Symptoms" section, changed the text

from "Authenticated Gaia users may cause code injection because of unprotected global variables usage when processing the HTTP request in TCL process"

to "After logging in to Gaia Portal, authenticated users (local Gaia users and RADIUS / TACACS users) may cause code injection in Gaia Portal because of unprotected global variables usage when processing the HTTP request in the TCL process"
- In the "Solution" section, changed the text

from "The solution adds a defense mechanism against code injections through special HTTP requests"

to "The solution adds a defense mechanism in Gaia Portal against code injections through special HTTP requests"
11 Nov 2024 In the "Solution" section, in the list "The fix is included starting from", added "Check Point Quantum R82"
07 Nov 2024 First release of this article

Article Properties

Access Level: General

Severity: Medium

Status: Approved

Date Created: 2024-10-08

Last Modified: 2025-02-09