CVE-2020-6020

Published Sep 24, 2020

Last updated 2 years ago

Overview

Description
Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38, can be manipulated to run commands as a high privileged user or crash, due to weak input validation on inputs by a trusted management administrator.
Source
cve@checkpoint.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
6.4
Impact score
5.5
Exploitability score
0.9
Vector string
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
7.4
Impact score
9.5
Exploitability score
5.1
Vector string
AV:A/AC:L/Au:S/C:C/I:C/A:P

Weaknesses

nvd@nist.gov
CWE-20
cve@checkpoint.com
CWE-20

Social media

Hype score
Not currently trending

Configurations