Impact: An unauthenticated attacker can run any command on the Management including run-script and exec-command on Security Gateway (Check Point Firewall).
Affected Products and versions:
Products: Security Management, Multi-Domain Security Management Server (MDS)
Limit Trusted Clients (GUI clients) to trusted IP addresses/subnets. To do so,
In SmartConsole, go to Manage & Settings > Permissions & Administrators > Trusted Clients.
Double-click the client you want to edit.
In the Trusted Client configuration window that opens, change the settings as needed and. Make sure do not use "Any" as a Type.
Click OK.
Protect Management access with Firewall, restrict access to tusted IP addresses, and verify that implied rules for control connections are enabled. This will create an implied rule that will prevent management access for non-authorized IP addresses.