The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://support.checkpoint.com/results/sk/sk183137 |
![]() ![]() |
History
Wed, 27 Aug 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Checkpoint gaia Os
Checkpoint mobile Access Checkpoint remote Access Vpn |
|
Weaknesses | CWE-22 | |
CPEs | cpe:2.3:a:checkpoint:mobile_access:-:*:*:*:*:*:*:* cpe:2.3:a:checkpoint:remote_access_vpn:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.10:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:*:*:*:*:*:*:* |
|
Vendors & Products |
Checkpoint gaia Os
Checkpoint mobile Access Checkpoint remote Access Vpn |
Thu, 07 Aug 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Checkpoint
Checkpoint check Point Checkpoint mobile Access Portal Agent |
|
Vendors & Products |
Checkpoint
Checkpoint check Point Checkpoint mobile Access Portal Agent |
Wed, 06 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 06 Aug 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway. | |
Title | Path Traversal | |
Weaknesses | CWE-35 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: checkpoint
Published: 2025-08-06T14:45:43.182Z
Updated: 2025-08-06T15:03:53.437Z
Reserved: 2024-11-17T08:00:07.201Z
Link: CVE-2024-52885

Updated: 2025-08-06T15:02:49.052Z

Status : Analyzed
Published: 2025-08-06T15:15:31.287
Modified: 2025-08-27T14:21:06.577
Link: CVE-2024-52885

No data.