CVE-2024-24914
HIGHDescription
Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.
Is your site exposed to CVE-2024-24914?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| checkpoint | gaia_os |
| checkpoint | gaia_os |
| checkpoint | gaia_os |
| checkpoint | clusterxl |
| checkpoint | multi-domain_management |
| checkpoint | quantum_6700 |
| checkpoint | quantum_maestro |
| checkpoint | quantum_scalable_chassis |
| checkpoint | quantum_security_gateway |
| checkpoint | quantum_security_management |
| checkpoint | quantum_spark |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-24914? +
How severe is CVE-2024-24914? +
What products are affected by CVE-2024-24914? +
How do I check if I'm vulnerable to CVE-2024-24914? +
Related Vulnerabilities
In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request …
A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation …
A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation …
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated …
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application …
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled …