sk183137 - Mobile Access File Share applications are vulnerable to directory traversal attacks
Mobile Access File Share applications are vulnerable to directory traversal attacks
Please read this important update from Check Point.
Security Alert:
- Severity: Medium
- Product: Mobile Access / SSL VPN
- Version: R81.10 (EOS), R81.20, R82
- OS: Gaia
- Last Modified: 2025-08-06
Symptoms
- The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.
Additionally, an authenticated, malicious end-user may create arbitrary files with 'nobody' permissions on the Mobile Access gateway's '/tmp' folder.
Access to file contents does not seem possible via the attack described above, as the vulnerable API is capable of directory listing and file upload only.
- This issue received the ID CVE-2024-52885
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 36
- Jumbo Hotfix Accumulator for R81.20 starting from Take 111
- Jumbo Hotfix Accumulator for R81.10 starting from Take 177
Article Properties
- Access Level: General
- Severity: Medium
- Status: Approved
- Date Created: 2025-02-12
- Last Modified: 2025-08-06