Impact: An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration. Check Point is aware that this vulnerability is being exploited, impacting a very small number of customers.
Affected Products and versions:
Products: Security Management Server, Multi-Domain Security Management Server (MDS)
Conditions: Successful remote exploit requires internet access to the Management Server IP address and no restrictions on Trusted Clients (GUI clients).
Limit Trusted Clients (GUI clients) to trusted IP addresses/subnets. To do so,
In SmartConsole, go to Manage & Settings > Permissions & Administrators > Trusted Clients.
Double-click the client you want to edit.
In the Trusted Client configuration window that opens, change the settings as needed and. Make sure do not use "Any" as a Type.
Click OK.
Protect Management access with Firewall, restrict access to tusted IP addresses, and verify that implied rules for control connections are enabled. This will create an implied rule that will prevent management access for non-authorized IP addresses.
How to Identify an Attack
In SmartConsole, go to Logs & Monitor / Logs & Events, and search for events where either the source IP or destination IP matches one of the known attacker IP addresses.
Attacker IP addresses
151.241.99.207
151.241.99.233
158.62.198.182
192.142.10.99
139.28.37.250
SmartConsole query
(src:151.241.99.207 OR dst:151.241.99.207 OR src:151.241.99.233 OR dst:151.241.99.233 OR src:158.62.198.182 OR dst:158.62.198.182 OR src:192.142.10.99 OR dst:192.142.10.99 OR src:139.28.37.250 OR dst:139.28.37.250)
In SmartConsole, go to Logs & Monitor / Logs & Events > Audit Logs View and search for the query "Authentication method: application token":