// For flags

CVE-2011-2664

Check Point Security Management Symlink Vulnerabilities

Severity Score

5.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Unspecified vulnerability in Check Point Multi-Domain Management / Provider-1 NGX R65, R70, R71, and R75, and SmartCenter during installation on non-Windows machines, allows local users on the MDS system to overwrite arbitrary files via unknown vectors.

Vulnerabilidad no especificada en Multi-Domain Management / Provider-1 NGX R65, R70, R71, y R75, y SmartCenter durante la instalación en máquinas no Windows, permite a usuarios locales en el sistema MDS sobrescribir archivos de su elección a través de vectores desconocidos.

Check Point Security Management Products suffer from multiple symlink vulnerabilities. Due to the combination of inadequate file checks, predictable file names and writing of temporary configuration files to /tmp it is possible for a unprivileged local user to exploit the post-installation script to overwrite arbitrary files on the security management system through symlink following. The script also contains a second-order symlink vulnerability which makes it possible for an attacker to gain control of the SMS configuration file: $FWDIR/conf/sofaware/SWManagementServer.ini.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-07-06 CVE Reserved
  • 2011-07-08 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Checkpoint
Search vendor "Checkpoint"
Multi-domain Management\/provider-1
Search vendor "Checkpoint" for product "Multi-domain Management\/provider-1"
ngx_r65
Search vendor "Checkpoint" for product "Multi-domain Management\/provider-1" and version "ngx_r65"
-
Affected
Checkpoint
Search vendor "Checkpoint"
Multi-domain Management\/provider-1
Search vendor "Checkpoint" for product "Multi-domain Management\/provider-1"
ngx_r70
Search vendor "Checkpoint" for product "Multi-domain Management\/provider-1" and version "ngx_r70"
-
Affected
Checkpoint
Search vendor "Checkpoint"
Multi-domain Management\/provider-1
Search vendor "Checkpoint" for product "Multi-domain Management\/provider-1"
ngx_r71
Search vendor "Checkpoint" for product "Multi-domain Management\/provider-1" and version "ngx_r71"
-
Affected
Checkpoint
Search vendor "Checkpoint"
Multi-domain Management\/provider-1
Search vendor "Checkpoint" for product "Multi-domain Management\/provider-1"
ngx_r75
Search vendor "Checkpoint" for product "Multi-domain Management\/provider-1" and version "ngx_r75"
-
Affected
Checkpoint
Search vendor "Checkpoint"
Multi-domain Management\/provider-1
Search vendor "Checkpoint" for product "Multi-domain Management\/provider-1"
ngx_smartcenter
Search vendor "Checkpoint" for product "Multi-domain Management\/provider-1" and version "ngx_smartcenter"
-
Affected