CVE-2021-30358: OS Command Injection
Published Oct 19, 2021
·Updated
Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from other locations by the Mobile Access Portal Agent.
Affected Software
5 affected components
Checkpoint Mobile Access Portal Agent=r80.20
Checkpoint Mobile Access Portal Agent=r80.30
Checkpoint Mobile Access Portal Agent=r80.40
Checkpoint Mobile Access Portal Agent=r81
Checkpoint Mobile Access Portal Agent=r81.10
Remediation
Patch Available
Event History
Oct 19, 2021
CVE Published
via MITRE·01:32 PM
Data Sourced
via MITRE·01:32 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-30358.
2
What is the severity of CVE-2021-30358?
The severity of CVE-2021-30358 is high (7.2).
3
Which software is affected by CVE-2021-30358?
The affected software is Checkpoint Mobile Access Portal Agent versions r80.20, r80.30, r80.40, r81, and r81.10.
4
How does CVE-2021-30358 work?
CVE-2021-30358 allows Mobile Access Portal Native Applications to run applications from other locations when the path is defined by the administrator with environment variables.
5
How can I fix CVE-2021-30358?
To fix CVE-2021-30358, please follow the instructions provided by Checkpoint in their support content.