The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.
📦
mobile_access
Vendor: checkpoint
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
0
Remote Access
Total CVEs
6
Total Indexed
Avg. EPSS
0.20%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
5.0
CVSS
Severity: MEDIUM
5.4
CVSS
For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties.
Severity: MEDIUM
3.5
CVSS
Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.
Severity: LOW