> Source: [sk142952](https://support.checkpoint.com/results/sk/sk142952)

# sk142952 - Check Point Products Acknowledgments

| Property | Value |
|----------|-------|
| Solution ID | sk142952 |
| Date Created | 2018-12-23 |
| Last Modified | 2026-01-27 |
| Technical Level | General |
| Products | Other |
| Versions | Not Version-Specific |

## Solution

**Check Point thanks the following parties for responsibly disclosing security issues in our products to help us improve our customers security.**   

*** ** * ** ***

2025
----

* David Cash, a Red Team Operator at AmberWolf, discovered a hardcoded token with excessive permissions to an SFTP server. The issue has been assigned [CVE-2025-3831](https://www.cve.org/CVERecord?id=CVE-2025-3831).
* Constantin Mader, Network Security Engineer at BearingPoint GmbH discovered two vulnerabilities related to exposure of sensitive information in Check Point's Identity Agent. They have been assigned with [CVE-2025-8304](https://www.cve.org/CVERecord?id=CVE-2025-8304) \& [CVE-2025-8305](https://www.cve.org/CVERecord?id=CVE-2025-8305)
* Konrad Porzezynski, Independent security researcher. Discovered lack of TLS validation when downloading a visualization support data (CSV) file in Management - Log Server. The issue has been assigned [CVE-2025-2028](https://nvd.nist.gov/vuln/detail/CVE-2025-2028)

*** ** * ** ***

2024
----

* Karol Mazurek - Head of Research, AFINE: Karol discovered a potential DLL Hijacking in the SmartConsole installation process. It has been assigned with [CVE-2024-24916](https://www.cve.org/CVERecord?id=CVE-2024-24916)
* Micha? Majchrowicz, Marcin Wyczechowski, and Pawe? Zdunek - members of the AFINE Team. All they are part of the team that discovered two different XSS vulnerabilities and on directory traversal on the Mobile Access portal - [CVE-2024-52885](https://www.cve.org/CVERecord?id=CVE-2024-52885), [CVE-2024-52887](https://www.cve.org/CVERecord?id=CVE-2024-52887) and [CVE-2024-52888](https://www.cve.org/CVERecord?id=CVE-2024-52888).
* Turgut Kaplanoglu for finding a Denial of Service vulnerability in Check Point Gateways when Threat Emulation blade is enabled.
* Pankaj Kumar Thakur for helping define new product features.
* Renato Garret�n for discovering local privilege escalation and running code in the context of ZoneAlarm process, using a crafted DLL ([CVE-2024-24910](https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-24910), [sk182219](https://support.checkpoint.com/results/sk/sk182219)).
* Pankaj Kumar Thakur of Green Tick Nepal Pvt. Ltd. for identifying improper validation in Check Point Harmony Mobile which led to in-tenant XSS issues.
* Pankaj Kumar Thakur for identifying information disclosure in Check Point ZoneAlarm.
* Davide Virruso for identifying code injection in Gaia Portal TCL substitution of global parameter values ([CVE-2024-24914](https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-24914), [sk182743](https://support.checkpoint.com/results/sk/sk182743)).
* Tian Yu from 360 Vulnerability Research Institute for identifying Out of Bounds read in the CPCA process on a Check Point Management Server ([CVE-2024-24911](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24911), [sk183101](https://support.checkpoint.com/results/sk/sk183101)).

*** ** * ** ***

2023
----

* Filip Dragovic working with Trend Micro Zero Day Initiative for discovering local privilege escalation in ZoneAlarm.
* Pankaj Kumar Thakur of Green Tick Nepal Pvt. Ltd. for identifying improper validation in Check Point Harmony security which led to in-tenant XSS issues.
* Constantin Mader for discovering issues with Check Point Harmony Connect suspension.
* Pankaj Kumar Thakur of Green Tick Nepal Pvt. Ltd. for identifying improper validation in Check Point Harmony browse which led to in-tenant GraphQL query injection.
* Constantin Mader for discovering several issues with 2FA in the Infinity Portal.
* Danny \& Rick of Pentests.nl for discovering privilege escalation using Gaia Portal hostnames page ([CVE-2023-28130](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28130), [sk181311](https://support.checkpoint.com/results/sk/sk181311)).
* Marius Gabriel Mihai and Andrea Intilangelo for discovering local privilege escalation issue in Check Point Harmony Connect Endpoint ([CVE-2023-28133](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28133), [sk181276](https://support.checkpoint.com/results/sk/sk181276)).
* Maxim Catanoi of LogicalPoint for discovering [insecure print of corporate password in Capsule Workspace Android application's log](https://support.checkpoint.com/results/sk/sk180670)
* Jochen Throm for discovering an issue with encryption password appearing in backup log ([sk180823](https://support.checkpoint.com/results/sk/sk180823)).

*** ** * ** ***

2022
----

* Sainikhil Turewale for discovering multiple cloud misconfigurations.
* Ashutosh Barot for discovering [CVE-2022-23746](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23746) ([sk180271](https://support.checkpoint.com/results/sk/sk180271)).
* Bahaa Naamneh for discovering a possible privilege escalation in Check Point Endpoint Security ([sk180044](https://support.checkpoint.com/results/sk/sk180044)).
* Yehia M. Elghaly for discovering a method to avoid phishing detection.
* Gabe Flawedworld for discovering [CVE-2022-23745](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23745) in Check Point Capsule Workspace (Fixed in Capsule workspace v8.2.2).
* Erwin Chan for discovering [CVE-2022-23744](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23744) in Check Point Harmony Endpoint (fixed in [Enterprise Endpoint Security E86.50 Windows Clients](https://support.checkpoint.com/results/sk/sk179044))
* Filip Dragovic for discovering [CVE-2022-23743](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23743) in Check Point ZoneAlarm (fixed in [ZoneAlarm 15.8.200.19118](https://www.zonealarm.com/software/extreme-security/release-history)).
* Alain R�del of cirosec GmbH for discovering [CVE-2022-23742](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23742) in Check Point Endpoint Security Client for Windows (fixed in [Enterprise Endpoint Security E86.40 Windows Clients](https://support.checkpoint.com/results/sk/sk178665)).

*** ** * ** ***

2021
----

* Christophe Schleypen of NATO Cyber Security Centre Pentesting for discovering [CVE-2021-30361](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30361) in Check Point Gaia Portal ([sk179128](https://support.checkpoint.com/results/sk/sk179128)).
* Ronnie Salomonsen of Mandiant for discovering [CVE-2021-30360](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30360) in Check Point Remote Access Client (fixed in [Check Point Remote Access Client E86.20](https://support.checkpoint.com/results/sk/sk176853)).
* Ronnie Salomonsen of Mandiant for discovering [CVE-2021-30359](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30359) in Check Point Harmony Browse and SandBlast Agent for Browsers installers (fixed in [Check Point Harmony Browse and SandBlast Agent for Browsers version 90.08.7405](https://support.checkpoint.com/results/sk/sk175968)).
* Raeez Abdulla of CodeGreen Systems for discovering [CVE-2021-30358](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30358) in Check Point Mobile Access Portal Agent (fixed in [Mobile Access Portal Agent build 800007042](https://support.checkpoint.com/results/sk/sk175806)).
* Jo�o Varelas for discovering [CVE-2021-30357](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30357) in Check Point SSL Network Extender Client for Linux (fixed in [SSL Network Extender Client for Linux build 800008302](https://support.checkpoint.com/results/sk/sk173513)).
* Mr. Tobias Neitzel of usd AG for discovering [CVE-2021-30356](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30356) in Check Point Identity Awareness Agent (fixed in [Identity Awareness Agent R81.018.0000](https://support.checkpoint.com/results/sk/sk134312)).
* Rotem Reiss for finding an information disclosure in Check Point docker hub image

*** ** * ** ***

2020
----

* Ubais PK for discovering [CVE-2020-6024](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6024) regarding a possible local privilege escalation in Check Point SmartConsole (fixed in [R81 SmartConsole Build 548](https://support.checkpoint.com/results/sk/sk170116), [R80.40 SmartConsole Build 415](https://support.checkpoint.com/results/sk/sk165473), [R80.30 SmartConsole Build 94](https://support.checkpoint.com/results/sk/sk153153), [R80.20 SmartConsole Build 119](https://support.checkpoint.com/results/sk/sk137593), [R80.10 SmartConsole Build 185](https://support.checkpoint.com/results/sk/sk119612)).
* Brenden Meeder of CyberArk Red Team for discovering [CVE-2020-6021](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6021) in Check Point Endpoint Security Client for Windows (fixed in [Enterprise Endpoint Security E84.20 Windows Clients](https://support.checkpoint.com/results/sk/sk170512)).
* Mads Joensen of Danish Cyber Defence for discovering [CVE-2020-6022](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6022) and [CVE-2020-6023](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6023) in Check Point ZoneAlarm Anti-Ransomware (fixed in [ZoneAlarm Extreme Security 15.8.139.18543](https://www.zonealarm.com/software/extreme-security/release-history)).
* Ido Hoorvich, Chen Erlich, and Nuttakorn Tungpoonsup+Ammarit Thongthua+Sittikorn Sangrattanapitak for (independently) discovering [CVE-2020-6015](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6015) in Check Point Endpoint Security Client for Windows (fixed in [Enterprise Endpoint Security E84.10 Windows Clients](https://support.checkpoint.com/results/sk/sk170117)).
* Chris Au for discovering [CVE-2020-6014](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6014) in Check Point Endpoint Security Client for Windows (fixed in [Enterprise Endpoint Security E83.20 Windows Clients](https://support.checkpoint.com/results/sk/sk168081)).
* Deniz Cevik of Cyberwise for discovering a couple of issues in the NGM app on the R80.40 Security Management, which is accessible only to configured administrators (fixed in [Jumbo HotFix R80.40 Take 83](https://support.checkpoint.com/results/sk/sk165456)).
* Eran Shimony for discovering an issue in the installation of Caspule Docs for Windows (fixed in [E83.20](https://support.checkpoint.com/results/sk/sk168081)).
* Mads Joensen of Danish Cyber Defence for discovering [CVE-2020-6012](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6012) in Check Point ZoneAlarm Anti-Ransomware (fixed in [ZoneAlarm Anti-Ransomware 1.0.713](https://www.zonealarm.com/anti-ransomware/release-history) and in [ZoneAlarm Extreme Security 15.8.125.18466](https://www.zonealarm.com/software/extreme-security/release-history)).
* Glenn Lloyd working with Trend Micro's Zero Day Initiative for discovering [CVE-2020-6013](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6013) in Check Point ZoneAlarm Firewall and Antivirus (fixed in [ZoneAlarm Extreme Security 15.8.109.18436](https://www.zonealarm.com/software/extreme-security/release-history)).
* Nikita Abramov and Mikhail Klyuchnikov of Positive Technologies for discovering [CVE-2020-6020](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6020) in the ICA Management Portal (fixed in [R80.40 Jumbo Hotfix Take 38](https://support.checkpoint.com/results/sk/sk165456), [R80.30 Jumbo Hotfix Take 210](https://support.checkpoint.com/results/sk/sk153152), [R80.20 Jumbo Hotfix Take 160](https://support.checkpoint.com/results/sk/sk137592), [R80.10 Jumbo Hotfix Take 278](https://support.checkpoint.com/results/sk/sk116380)).

*** ** * ** ***

2019
----

* Eran Shimony for discovering [CVE-2019-8463](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8463) in the installation of the Check Point Endpoint Security Client for Windows (fixed in[Enterprise Endpoint Security E82.10 Windows Clients](https://support.checkpoint.com/results/sk/sk163578)).
* Peleg Hadar of SafeBreach Labs for discovering [CVE-2019-8461](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8461) in the Initial Client of Check Point Endpoint Security for Windows (fixed in [Enterprise Endpoint Security E81.30 Windows Clients](https://support.checkpoint.com/results/sk/sk160812)).
* Peleg Hadar of SafeBreach Labs for responsibly disclosing a local privilege escalation issue in ZoneAlarm, that was fixed in version 15.6.121.18102 (see: [ZoneAlarm Extreme Security - Release History](https://www.zonealarm.com/software/extreme-security/release-history)).
* George Karagiannidis of TwelveSec for discovering [CVE-2019-8459](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8459) in the VPN blade of the Endpoint Client for Windows (fixed in [Enterprise Endpoint Security E80.83 Windows Clients](https://support.checkpoint.com/results/sk/sk124972)).
* Edsel Valle of NSS Labs for discovering [CVE-2019-8458](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8458) in the Anti-Malware blade of the Endpoint Client for Windows (fixed in [Enterprise Endpoint Security E81.00 Windows Clients](https://support.checkpoint.com/results/sk/sk153053)).
* Jakub Palaczynski for finding issues in ZoneAlarm and the Endpoint Client for Windows: [CVE-2019-8452](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8452), [CVE-2019-8453](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8453), [CVE-2019-8454](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8454), [CVE-2019-8455](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8455) (fixed in [ZoneAlarm](https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.260.17960) and [Enterprise Endpoint Security E80.96 Windows Clients](https://support.checkpoint.com/results/sk/sk150012)).

*** ** * ** ***

2018
----

* Chris Anastasio of Illumant for his finding that ZoneAlarm's SBACipollaSrvHost exposes a WCF service to low privilege users which can be leveraged to execute arbitrary code as SYSTEM ([ZoneAlarm� Free Firewall](https://www.zonealarm.com/software/release-history/zafree.html#15.4.062.17802) \& [ZoneAlarm� Free Antivirus + Firewall](https://www.zonealarm.com/software/release-history/zafavfw.html#15.4.062.17802)): [CVE-2018-8790](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8790).
* Boris PARAT of Manhattan SA for improving the protection [CPAI-2016-0003](https://www.checkpoint.com/defense/advisories/public/2016/cpai-2016-0003.html) to cover more cases.
* Okan CO?KUN for issues in the UDM Portal's web server.

*** ** * ** ***

2017
----

* Bogner Florian for a local privilege escalation attack in ZoneAlarm's Anti-Virus (fixed in version [15.1.501.17249](https://www.zonealarm.com/software/release-history/zafavfw.html#15.1.501.17249)).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
