important · Management plane — Check Point
A pre-authentication FWM login overflow may execute code as root on Check Point management servers.
Affects
Check Point Quantum Security Management and Log Servers, including Multi-Domain and standalone deployments that manage network-security policy.
An address admitted by Trusted Clients can send an oversized username before authentication and corrupt the stack of the root-running FWM process.
Detail and 2 sources
Chain to watch
Reach FWM from a Trusted Clients address→↓Overflow the pre-authentication username stack buffer→↓Attempt controlled execution in the root process→↓Controlled root execution remains unproven.
Unverified chainPublish a reproducer that demonstrates controlled instruction flow or a benign command under the FWM process.
A patch exists, but controlled root execution has not been demonstrated in the held public evidence.