> Source: [sk148792](https://support.checkpoint.com/results/sk/sk148792)

# sk148792 - Check Point Response to BMC Vulnerability (Pantsdown, CVE-2019-6260)

| Property | Value |
|----------|-------|
| Solution ID | sk148792 |
| Date Created | 2019-03-08 |
| Last Modified | 2019-09-25 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Hardware |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, Not Version-Specific, R82.20 |
| OS | Gaia |
| Platform | Smart-1, 15000, 5000, 6000, TE |

## Symptoms

- Researchers have released information about a vulnerability in ASPEED BMC controllers AST2400 and AST2500 which allows unauthorized read and write access to the BMC memory from the local host. For more information see:  

* <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6260>
* <https://nvd.nist.gov/vuln/detail/CVE-2019-6260>
* <https://www.flamingspork.com/blog/2019/01/23/cve-2019-6260:-gaining-control-of-bmc-from-the-host-processor/>

## Cause

Access to the BMC memory is possible without authentication via Advanced High-Performance Bus (AHB).

## Solution

There is no added risk to Check Point appliances, since code execution privileges are to be provided to trusted administrators only and exploiting this vulnerability requires such code execution on the Check Point host.  
Using this exploit via network is not possible because the BMC console UART is not used in Check Point appliances.

A fix is integrated into released LOM firmware 2.43n (specific Smart-1 devices) and 3.35g (5000/15000/23000 devices). It is available for download in [sk88064](http://supportcontent.checkpoint.com/solutions?id=sk88064 "sk88064").

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
