CVE-2024-24914

HIGH EPSS 31.5%
Published Nov 7, 20241y ago · Modified Jun 17, 20261w ago
8.0 CVSS 3.1
High
Find Similar
Published Nov 7, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.

CVSS Details

Base Score
8.0
Exploitability
2.1
Impact
5.9
Vector string
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Adjacent
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
31.5% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-914

Affected Products 11

VendorProductVersionRange
checkpointgaia_osr81any
checkpointgaia_osr81.10any
checkpointgaia_osr81.20any
checkpointclusterxl*any
checkpointmulti-domain_management*any
checkpointquantum_6700*any
checkpointquantum_maestro*any
checkpointquantum_scalable_chassis*any
checkpointquantum_security_gateway*any
checkpointquantum_security_management*any
checkpointquantum_spark*any

References 1

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.