← Back

Checkpoint

checkpoint

131 CVEs • 95 products

Products (95)

Click to collapse
Toggle
Firewall 1
firewall-1
Vpn 1
vpn-1
Zonealarm
zonealarm
Gaia Os
gaia_os
Provider 1
provider-1
Connectra Ngx
connectra_ngx
Smartconsole
smartconsole
Mobile Access
mobile_access
Gaia Portal
gaia_portal
Zonealarm Pro
zonealarm_pro
Ng Ai
ng-ai
Check Point
check_point
Express
express
Vpn 1 Utm Edge
vpn-1_utm_edge
Ipso Os
ipso_os
Ipsec Vpn
ipsec_vpn
Capsule Docs
capsule_docs
Harmony Browse
harmony_browse
Log Server
log_server
Harmony Sase
harmony_sase
Gaia Embedded
gaia_embedded
Gaia
gaia
Quantum Spark
quantum_spark
Clusterxl
clusterxl
Quantum 6700
quantum_6700

CVEs (131)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Checkpoint
2Endpoint Security
Harmony Endpoint
Jun 17, 2026
Jul 7, 2022
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed to disable endpoint protection by a local administrator.
1Checkpoint
1Endpoint Security
Jun 17, 2026
May 12, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, s...Show more
Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links.Show less
1Checkpoint
2Gaia Os
Gaia Portal
Jun 17, 2026
May 11, 2022
N/A· v4
6.7 MEDIUM· v3
6.9 MEDIUM· v2
The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS.
1Checkpoint
1Zonealarm
Jun 17, 2026
May 11, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permissions in the ProgramData\CheckPoint\ZoneAlarm\Data\Updates directory all...Show more
Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permissions in the ProgramData\CheckPoint\ZoneAlarm\Data\Updates directory allow a local attacker the ability to execute an arbitrary file write, leading to execution of code as local system, in ZoneAlarm versions before v15.8.211.192119Show less
1Checkpoint
1Endpoint Security
Jun 17, 2026
Jan 10, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE i...Show more
Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE in the repair folder which runs with the Check Point Remote Access Client privileges.Show less
1Checkpoint
2Harmony Browse
Sandblast Agent For Browsers
Jun 17, 2026
Oct 22, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because the MS Installer allows regular users to repair their installation, an...Show more
The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because the MS Installer allows regular users to repair their installation, an attacker running an installer before 90.08.7405 can start the installation repair and place a specially crafted binary in the repair folder, which runs with the admin privileges.Show less
1Checkpoint
1Mobile Access Portal Agent
Jun 17, 2026
Oct 19, 2021
N/A· v4
7.2 HIGH· v3
6.0 MEDIUM· v2
Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from other locations by the Mobile Access Portal Agent.
1Checkpoint
1Ssl Network Extender
Jun 17, 2026
Jun 8, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access.
1Checkpoint
1Identity Agent
Jun 17, 2026
Apr 22, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low privileged users to overwrite protected system files.
12Checkpoint
DebianFedoraproject+9 more
106Active Iq Unified Manager
Capture ClientCloud Volumes Ontap Mediator+103 more
Jun 17, 2026
Mar 25, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the...Show more
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).Show less
1Checkpoint
1Smartconsole
Jun 17, 2026
Jan 20, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running execut...Show more
Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all authenticated users.Show less
1Checkpoint
1Endpoint Security
Jun 17, 2026
Dec 3, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, a...Show more
Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted DLL in the repair folder which will run with the Endpoint client’s privileges.Show less
1Checkpoint
1Endpoint Security
Jun 17, 2026
Nov 5, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Check Point Endpoint Security for Windows before E84.10 can reach denial of service during clean install of the client which will prevent the storage of service log files in non-standard locations.
1Checkpoint
1Endpoint Security
Jun 17, 2026
Nov 2, 2020
N/A· v4
6.5 MEDIUM· v3
4.4 MEDIUM· v2
Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for the Domain Name. An attacker with administr...Show more
Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for the Domain Name. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.Show less
1Checkpoint
1Zonealarm
Jun 17, 2026
Oct 27, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware.
1Checkpoint
1Zonealarm
Jun 17, 2026
Oct 27, 2020
N/A· v4
5.5 MEDIUM· v3
3.6 LOW· v2
Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files in Anti-Ransomware.
1Checkpoint
1Ica Management Portal
Jun 17, 2026
Sep 24, 2020
N/A· v4
6.4 MEDIUM· v3
7.4 HIGH· v2
Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38, can be manipulated to run commands as a high privileged user or crash,...Show more
Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38, can be manipulated to run commands as a high privileged user or crash, due to weak input validation on inputs by a trusted management administrator.Show less
1Checkpoint
1Zonealarm Anti Ransomware
Jun 17, 2026
Aug 4, 2020
N/A· v4
7.4 HIGH· v3
4.4 MEDIUM· v2
ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiti...Show more
ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links. This allows an unprivileged user to enable escalation of privilege via local access.Show less
1Checkpoint
1Zonealarm Extreme Security
Jun 17, 2026
Jul 6, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation...Show more
ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched systems.Show less
1Checkpoint
1Endpoint Security Clients
Jun 17, 2026
Dec 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations.