Security updates have been released by Check Point to fix a high severity authentication-bypass vulnerability affecting Security Management Server and Multi-Domain Security Management Server deployments in several Check Point releases. An attacker with network access can bypass Management authentication and execute arbitrary commands on the targeted management server without authentication, Check Point says. An attack could result in complete compromise of the Security Management system including firewall policies, gateway configurations, administrator access and the managed security infrastructure.

The flaw impacts R80, R80.10, R80.20, R80.30, R80.40, R81 and R81.10, all of which are no longer supported. Impacts versions R81.20, R82, R82.10. However, the possible effect is worth patching quickly as Security Management Servers generally have privileged access to enterprise firewall configurations and security policy controls.

If organizations do not restrict their Trusted Clients, allow GUI client connections from broad network ranges or expose management services to untrusted networks, their security risks increase. Check the logs for unusual management connections, unusual admin activity, or unusual command execution that may indicate a compromise attempt. The Security Management Server is the central control plane, and that could enable an attacker to modify security policies, create privileged accounts, disable protections or pivot into managed environments.