CVE-2020-6020
Summary
| CVE | CVE-2020-6020 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-24 14:15:00 UTC |
| Updated | 2022-11-16 13:56:00 UTC |
| Description | Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38, can be manipulated to run commands as a high privileged user or crash, due to weak input validation on inputs by a trusted management administrator. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Checkpoint | Ica Management Portal | All | All | All | All |
| Application | Checkpoint | Ica Management Portal | r80.10 | - | All | All |
| Application | Checkpoint | Ica Management Portal | r80.20 | - | All | All |
| Application | Checkpoint | Ica Management Portal | r80.20 | take_156 | All | All |
| Application | Checkpoint | Ica Management Portal | r80.30 | - | All | All |
| Application | Checkpoint | Ica Management Portal | r80.30 | take_200 | All | All |
| Application | Checkpoint | Ica Management Portal | r80.40 | - | All | All |
| Application | Checkpoint | Ica Management Portal | All | All | All | All |
| Application | Checkpoint | Ica Management Portal | r80.20 | - | All | All |
| Application | Checkpoint | Ica Management Portal | r80.20 | take_156 | All | All |
| Application | Checkpoint | Ica Management Portal | r80.30 | - | All | All |
| Application | Checkpoint | Ica Management Portal | r80.30 | take_200 | All | All |
| Application | Checkpoint | Ica Management Portal | r80.40 | - | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Check Point Products' Acknowledgments | MISC | supportcontent.checkpoint.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.