← Back

Checkpoint

checkpoint

131 CVEs • 95 products

Products (95)

Click to collapse
Toggle
Firewall 1
firewall-1
Vpn 1
vpn-1
Zonealarm
zonealarm
Gaia Os
gaia_os
Provider 1
provider-1
Connectra Ngx
connectra_ngx
Smartconsole
smartconsole
Mobile Access
mobile_access
Gaia Portal
gaia_portal
Zonealarm Pro
zonealarm_pro
Ng Ai
ng-ai
Check Point
check_point
Express
express
Vpn 1 Utm Edge
vpn-1_utm_edge
Ipso Os
ipso_os
Ipsec Vpn
ipsec_vpn
Capsule Docs
capsule_docs
Harmony Browse
harmony_browse
Log Server
log_server
Harmony Sase
harmony_sase
Gaia Embedded
gaia_embedded
Gaia
gaia
Quantum Spark
quantum_spark
Clusterxl
clusterxl
Quantum 6700
quantum_6700

CVEs (131)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Checkpoint
1Security Gateway
Jun 17, 2026
Oct 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In a rare scenario, Check Point R80.30 Security Gateway before JHF Take 50 managed by Check Point R80.30 Management crashes with a unique configuration of enhanced logging.
1Checkpoint
3Capsule Docs Standalone Client
Endpoint SecurityRemote Access Clients
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE...Show more
Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location accessible with write permissions to the user.Show less
1Checkpoint
6Capsule Docs Standalone Client
Endpoint Security ClientsEndpoint Security Server Package+3 more
Jun 17, 2026
Jun 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar...Show more
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.Show less
1Checkpoint
3Capsule Docs
Endpoint Security ClientsRemote Access Clients
Jun 17, 2026
Jun 20, 2019
N/A· v4
4.4 MEDIUM· v3
3.5 LOW· v2
Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges...Show more
Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.Show less
1Checkpoint
1Endpoint Security
Jun 17, 2026
Apr 29, 2019
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can writ...Show more
A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into that file that will later be run by the user or the system.Show less
1Checkpoint
2Endpoint Security
Zonealarm
Jun 17, 2026
Apr 22, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all us...Show more
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file.Show less
1Checkpoint
1Zonealarm
Jun 17, 2026
Apr 17, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited acce...Show more
A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file.Show less
1Checkpoint
1Zonealarm
Jun 17, 2026
Apr 17, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Deni...Show more
Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client.Show less
1Checkpoint
1Ipsec Vpn
Jun 17, 2026
Apr 9, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server.
1Checkpoint
1Zonealarm
Jun 17, 2026
Mar 1, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Check Point ZoneAlarm version 15.3.064.17729 and below expose a WCF service that can allow a local low privileged user to execute arbitrary code as SYSTEM.
1Checkpoint
1Security Gateway
May 6, 2026
Nov 16, 2014
N/A· v4
N/A· v3
7.1 HIGH· v2
Multiple unspecified vulnerabilities in Check Point Security Gateway R75.40VS, R75.45, R75.46, R75.47, R76, R77, and R77.10, when the (1) IPS blade, (2) IPsec Remote Access, (3) Mobile Access / SSL VPN blade, (4) SSL Net...Show more
Multiple unspecified vulnerabilities in Check Point Security Gateway R75.40VS, R75.45, R75.46, R75.47, R76, R77, and R77.10, when the (1) IPS blade, (2) IPsec Remote Access, (3) Mobile Access / SSL VPN blade, (4) SSL Network Extender, (5) Identify Awareness blade, (6) HTTPS Inspection, (7) UserCheck, or (8) Data Leak Prevention blade module is enabled, allow remote attackers to cause a denial of service ("stability issue") via an unspecified "traffic condition."Show less
1Checkpoint
1Security Gateway
May 6, 2026
Nov 16, 2014
N/A· v4
N/A· v3
7.1 HIGH· v2
Unspecified vulnerability in Check Point Security Gateway R75, R76, R77, and R77.10, when UserCheck is enabled and the (1) Application Control, (2) URL Filtering, (3) DLP, (4) Threat Emulation, (5) Anti-Bot, or (6) Anti-...Show more
Unspecified vulnerability in Check Point Security Gateway R75, R76, R77, and R77.10, when UserCheck is enabled and the (1) Application Control, (2) URL Filtering, (3) DLP, (4) Threat Emulation, (5) Anti-Bot, or (6) Anti-Virus blade is used, allows remote attackers to cause a denial of service (fwk0 process crash, core dump, and restart) via a redirect to the UserCheck page.Show less
1Checkpoint
1Security Gateway
May 6, 2026
Nov 16, 2014
N/A· v4
N/A· v3
7.1 HIGH· v2
Unspecified vulnerability in Check Point Security Gateway R77 and R77.10, when the (1) URL Filtering or (2) Identity Awareness blade is used, allows remote attackers to cause a denial of service (crash) via vectors invol...Show more
Unspecified vulnerability in Check Point Security Gateway R77 and R77.10, when the (1) URL Filtering or (2) Identity Awareness blade is used, allows remote attackers to cause a denial of service (crash) via vectors involving an HTTPS request.Show less
17Apple
AristaCanonical+14 more
74Arx Firmware
BashBig Ip Access Policy Manager+71 more
Apr 22, 2026
Sep 25, 2014
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth...Show more
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.Show less
17Apple
AristaCanonical+14 more
74Arx Firmware
BashBig Ip Access Policy Manager+71 more
Apr 22, 2026
Sep 24, 2014
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vec...Show more
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.Show less
1Checkpoint
1Security Gateway
May 6, 2026
Apr 1, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Check Point Security Gateway 80 R71.x before R71.45 (730159141) and R75.20.x before R75.20.4 and 600 and 1100 appliances R75.20.x before R75.20.42 have unknown impact and attack ve...Show more
Multiple unspecified vulnerabilities in Check Point Security Gateway 80 R71.x before R71.45 (730159141) and R75.20.x before R75.20.4 and 600 and 1100 appliances R75.20.x before R75.20.42 have unknown impact and attack vectors related to "important security fixes."Show less
1Checkpoint
1Session Authentication Agent
Apr 29, 2026
Jan 26, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Check Point Session Authentication Agent allows remote attackers to obtain sensitive information (user credentials) via unspecified vectors.
1Checkpoint
2Management Server
Security Gateway
Apr 29, 2026
Jan 26, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Check Point R75.47 Security Gateway and Management Server does not properly enforce Anti-Spoofing when the routing table is modified and the "Get - Interfaces with Topology" action is performed, which allows attackers to...Show more
Check Point R75.47 Security Gateway and Management Server does not properly enforce Anti-Spoofing when the routing table is modified and the "Get - Interfaces with Topology" action is performed, which allows attackers to bypass intended access restrictions.Show less
1Checkpoint
2Gaia Os
Ipso Os
Apr 29, 2026
Jan 23, 2014
N/A· v4
N/A· v3
5.4 MEDIUM· v2
The OSPF implementation in Check Point Gaia OS R75.X and R76 and IPSO OS 6.2 R75.X and R76 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing o...Show more
The OSPF implementation in Check Point Gaia OS R75.X and R76 and IPSO OS 6.2 R75.X and R76 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.Show less
1Checkpoint
1Endpoint Security Mi Server R73
Apr 29, 2026
Jan 22, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Check Point Endpoint Security MI Server through R73 3.0.0 HFA2.5 does not configure X.509 certificate validation for client devices, which allows man-in-the-middle attackers to spoof SSL servers by presenting an arbitrar...Show more
Check Point Endpoint Security MI Server through R73 3.0.0 HFA2.5 does not configure X.509 certificate validation for client devices, which allows man-in-the-middle attackers to spoof SSL servers by presenting an arbitrary certificate during a session established by a client.Show less