Where
AND
-Infinity
0

Vendor Risk Score

See how checkpoint compares to other vendors in security performance

View Risk Score →

Software

checkpoint gaia embedded
2
checkpoint gaia os
2
checkpoint multi-domain security management
2
checkpoint quantum security management
2
checkpoint quantum spark 1530
2
checkpoint quantum spark 1535
2
checkpoint quantum spark 1550
2
checkpoint quantum spark 1555
2
checkpoint quantum spark 1570
2
checkpoint quantum spark 1570r
2
checkpoint quantum spark 1575
2
checkpoint quantum spark 1575r
2
checkpoint quantum spark 1590
2
checkpoint quantum spark 1595r
2
checkpoint quantum spark 1600
2
checkpoint quantum spark 1800
2
checkpoint quantum spark 1900
2
checkpoint quantum spark 2000
2
checkpoint quantum spark 2530
2
checkpoint quantum spark 2550
2
checkpoint quantum spark 2560
2
checkpoint quantum spark 2570
2
checkpoint quantum spark 2580
2
checkpoint quantum spark 2590
2
checkpoint security gateway
2
checkpoint cloudguard network security
1
checkpoint quantum 3600
1
checkpoint quantum 3800
1
checkpoint quantum force 19100
1
checkpoint quantum force 19200
1
checkpoint quantum force 29100
1
checkpoint quantum force 29200
1
checkpoint quantum force 3920
1
checkpoint quantum force 3950
1
checkpoint quantum force 3970
1
checkpoint quantum force 3980
1
checkpoint quantum force 9100
1
checkpoint quantum force 9200
1
checkpoint quantum force 9300
1
checkpoint quantum force 9400
1
checkpoint quantum force 9700
1
checkpoint quantum force 9800
1
checkpoint quantum lightspeed mls200
1
checkpoint quantum lightspeed mls400
1
checkpoint quantum lightspeed qls250
1
checkpoint quantum lightspeed qls450
1
checkpoint quantum lightspeed qls650
1
checkpoint quantum lightspeed qls800
1
checkpoint quantum security gateway
1
checkpoint quantum security gateway firmware
1
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

1 / 2
Source: CISA
First published (updated )
Severity
9.8
EPSS
2.42%
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

1 / 2
Source: MITRE
First published (updated )
Severity
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

1 / 2
Source: MITRE
First published (updated )
Severity
8.6
Infoleak
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.

1 / 2
Source: CISA
First published (updated )
Severity
9.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

1 / 2
Source: MITRE
First published (updated )
Severity
9.8
OS Command Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A flaw was found in the bash functionality that evaluates specially formatted environment variables passed to it from another environment. An attacker could use this feature to override or bypass restrictions to the environment to execute shell commands before restrictions have been applied. Certain services and applications allow remote unauthenticated attackers to provide environment variables, allowing them to exploit this issue.

Acknowledgements:

Red Hat would like to thank Stephane Chazelas for reporting this issue.

1 / 3
Source: Red Hat
First published (updated )
Severity
9.8
OS Command Injection
AV:N/AC:L/Au:N/C:C/I:C/A:C

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the modcgi and modcgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

1 / 2
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203