Checkpoint ICA Management Tool 命令执行和拒绝服务漏洞

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

# Vulnerabilities in Checkpoint ICA Management Tool Written by [Mikhail Klyuchnikov](https://swarm.ptsecurity.com/author/mikhail- klyuchnikov/ "Posts by Mikhail Klyuchnikov") and [Nikita Abramov](https://swarm.ptsecurity.com/author/nikita-abramov/ "Posts by Nikita Abramov") on November 25, 2020 ![](https://images.seebug.org/1606369667823-w331s) Today we will be analysing multiple vulnerabilities that we found in a component of Checkpoint Security Management, which is used in Check Point products. The component in question is the ICA Management Tool. The ICA Management Tool helps to manage user certificates: * Run searches * Recreate CRLs * Configure the ICA * Remove expired certificates By default, this service is turned off, and to turn it on you need to use the built-in utility `cpca_client`. For example, you can run the command `cpca_client set_mgmt_tool on -no_ssl`, but be careful: if you run that command, the service will be available to users without authentication. We...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息