VYPR

Vendor CVEs

Checkpoint

All CVEs

152 total · sorted by risk
  • CVE-2014-7169CriKEVSep 25, 2014
    risk 0.87cvss 9.8epss 1.00

    GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by…

  • CVE-2014-6271CriKEVSep 24, 2014
    risk 0.87cvss 9.8epss 1.00

    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd,…

  • CVE-2024-24919HigKEVMay 28, 2024
    risk 0.85cvss 8.6epss 1.00

    Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

  • CVE-2026-16232CriKEVJul 22, 2026
    risk 0.81cvss 9.8epss 0.73

    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to…

  • CVE-2026-50751CriKEVJun 8, 2026
    risk 0.80cvss 9.3epss 0.83

    A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

  • CVE-2019-8459CriJun 20, 2019
    risk 0.64cvss 9.8epss 0.01

    Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.

  • CVE-2026-18574CriAug 3, 2026
    risk 0.61cvss epss 0.01

    An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management…

  • CVE-2022-41604HigSep 27, 2022
    risk 0.57cvss 8.8epss 0.01

    Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\ZoneAlarm\Data\Updates directory, and a self-protection driver bypass that allows creation of a…

  • CVE-2020-6013HigJul 6, 2020
    risk 0.57cvss 8.8epss 0.02

    ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched…

  • CVE-2019-8452HigApr 22, 2019
    risk 0.54cvss 7.8epss 0.01

    A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with…

  • CVE-2026-48132HigMay 26, 2026
    risk 0.53cvss 8.1epss 0.02

    The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary…

  • CVE-2026-48131HigMay 26, 2026
    risk 0.53cvss 8.1epss 0.03

    The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related…

  • CVE-2025-3831HigAug 12, 2025
    risk 0.53cvss 8.1epss 0.00

    Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.

  • CVE-2021-30356HigApr 22, 2021
    risk 0.53cvss 8.1epss 0.01

    A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low privileged users to overwrite protected system files.

  • CVE-2024-24914HigNov 7, 2024
    risk 0.52cvss 8.0epss 0.00

    Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.

  • CVE-2026-10847HigJun 11, 2026
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process.…

  • CVE-2024-6233HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Check Point ZoneAlarm Extreme Security. An attacker must first obtain the ability to…

  • CVE-2023-28134HigNov 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

  • CVE-2023-28133HigJul 23, 2023
    risk 0.51cvss 7.8epss 0.06

    Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file

  • CVE-2022-23742HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.04

    Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or…

  • CVE-2022-23743HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permissions in the ProgramData\CheckPoint\ZoneAlarm\Data\Updates directory allow a local attacker the ability to execute an arbitrary…

  • CVE-2021-30360HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.01

    Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE in the repair folder which runs with the Check Point Remote…

  • CVE-2021-30359HigOct 22, 2021
    risk 0.51cvss 7.8epss 0.04

    The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because the MS Installer allows regular users to repair their installation, an attacker running an installer before 90.08.7405 can start…

  • CVE-2020-6024HigJan 20, 2021
    risk 0.51cvss 7.8epss 0.00

    Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all…

  • CVE-2020-6021HigDec 3, 2020
    risk 0.51cvss 7.8epss 0.00

    Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a…

  • CVE-2020-6023HigOct 27, 2020
    risk 0.51cvss 7.8epss 0.00

    Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware.

  • CVE-2019-8461HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.01

    Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location…

  • CVE-2018-8790HigMar 1, 2019
    risk 0.51cvss 7.8epss 0.00

    Check Point ZoneAlarm version 15.3.064.17729 and below expose a WCF service that can allow a local low privileged user to execute arbitrary code as SYSTEM.

  • CVE-2008-0662HigFeb 8, 2008
    risk 0.51cvss 7.8epss 0.00

    The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to gain privileges by reading and reusing…

  • CVE-2022-23745HigJul 18, 2022
    risk 0.50cvss 7.5epss 0.16

    A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS). This could result in application crashing but could not be used to gather any sensitive information.

  • CVE-2004-0079HigNov 23, 2004
    risk 0.50cvss 7.5epss 0.10

    The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

  • CVE-2026-48133HigMay 26, 2026
    risk 0.49cvss 7.5epss 0.05

    When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.

  • CVE-2023-28130HigJul 26, 2023
    risk 0.49cvss 7.2epss 0.21

    Local user may lead to privilege escalation using Gaia Portal hostnames page.

  • CVE-2022-23746HigNov 30, 2022
    risk 0.49cvss 7.5epss 0.01

    The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords.

  • CVE-2021-30358HigOct 19, 2021
    risk 0.49cvss 7.2epss 0.27

    Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from other locations by the Mobile Access Portal Agent.

  • CVE-2019-8463HigDec 23, 2019
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations.

  • CVE-2019-8462HigOct 2, 2019
    risk 0.49cvss 7.5epss 0.01

    In a rare scenario, Check Point R80.30 Security Gateway before JHF Take 50 managed by Check Point R80.30 Management crashes with a unique configuration of enhanced logging.

  • CVE-2026-50752HigJun 8, 2026
    risk 0.48cvss 7.4epss 0.05

    A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful…

  • CVE-2020-6012HigAug 4, 2020
    risk 0.48cvss 7.4epss 0.01

    ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic…

  • CVE-2024-24910HigApr 18, 2024
    risk 0.47cvss 7.3epss 0.00

    A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged…

  • CVE-2019-8454HigApr 29, 2019
    risk 0.46cvss 7.0epss 0.00

    A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into that file that will later be run by the…

  • CVE-2019-8455HigApr 17, 2019
    risk 0.46cvss 7.1epss 0.00

    A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file.

  • CVE-2024-24912MedMay 1, 2024
    risk 0.44cvss 6.7epss 0.00

    A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and below. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.

  • CVE-2021-30361MedMay 11, 2022
    risk 0.44cvss 6.7epss 0.04

    The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS.

  • CVE-2021-3449MedMar 25, 2021
    risk 0.43cvss 5.9epss 0.63

    An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a…

  • CVE-2025-8305MedDec 22, 2025
    risk 0.42cvss 6.5epss 0.00

    An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in Identity Agent for Terminal Services debug files.

  • CVE-2025-8304MedDec 22, 2025
    risk 0.42cvss 6.5epss 0.00

    An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being accessible in the Windows Registry keys for Check Point Identity Agent running on a Terminal Server.

  • CVE-2025-2028MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

  • CVE-2024-24916MedJun 19, 2025
    risk 0.42cvss 6.5epss 0.02

    Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).

  • CVE-2020-6014MedNov 2, 2020
    risk 0.42cvss 6.5epss 0.00

    Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for the Domain Name. An attacker with administrator privileges can leverage this to gain code execution…

Page 1 of 4