Horizon Alert
Summary of the vulnerability and why it matters
This critical vulnerability affects Check Point's SmartConsole login process, allowing unauthenticated remote attackers to gain full administrative control. Exploitation could lead to unauthorized modifications of security policies and configurations. While Check Point is aware of active exploitation impacting a small number of customers, confirming relevance and exposure is the primary concern.
- Unauthenticated access to administrative privileges.
- Enables unauthorized security policy changes.
- Confirm relevance and exposure to network.
Attack Path
How an attacker could exploit the issue
An attacker can bypass authentication to gain administrative access to Check Point's SmartConsole by remotely accessing the Management Server IP address, provided the environment allows for trusted client restrictions to be bypassed. Once access is established, the attacker can obtain a login token, which then allows them to authenticate with full administrative privileges to modify security policies and configurations. The vulnerability is known to be actively exploited.
- Requires internet access to Management Server.
- Bypasses login to obtain administrative token.
- Allows modification of security policies.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated remote attacker could bypass authentication to gain full administrative privileges on the Check Point Management Server. This attack requires internet access to the Management Server and a specific configuration that does not restrict trusted clients. Successful exploitation could allow an attacker to alter critical security policies and configurations.
- Security policies and configurations at risk.
- Bypass authentication to gain admin access.
- Modify security settings and configurations.
Operational Fix
Recommended remediation, mitigation, and detection steps
Security and infrastructure teams are likely responsible for addressing this critical authentication bypass in Check Point SmartConsole. The initial step involves identifying all instances of the affected technology, assessing their internet exposure and business criticality, and confirming the accountable owner. A risk-based remediation plan should then be developed in coordination with the vendor.
- Own by: Security and infrastructure teams.
- Verify first: Internet exposure and criticality.
- Action: Plan vendor-coordinated remediation.