Vulnerability Description
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkpoint | Mobile Access | - |
| Checkpoint | Remote Access Vpn | - |
| Checkpoint | Gaia Os | r81.10 |
Related Weaknesses (CWE)
References
- https://support.checkpoint.com/results/sk/sk183137Vendor Advisory
FAQ
What is CVE-2024-52885?
CVE-2024-52885 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to li...
How severe is CVE-2024-52885?
CVE-2024-52885 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-52885?
Check the references section above for vendor advisories and patch information. Affected products include: Checkpoint Mobile Access, Checkpoint Remote Access Vpn, Checkpoint Gaia Os.