A significant security bypass vulnerability exists within Check Point's SmartConsole management platform, enabling unauthenticated attackers to gain full administrative control over Security Management Servers and Multi-Domain Security Management Servers (MDS). Check Point SmartConsole Zero-Day Instead of relying on an authenticated identity, vulnerable versions accept an attacker-supplied Secure Internal Communication (SIC) distinguished name (DN) as a substitute. Exploitation Chain: 1.

This token is used to issue a gen-sso-token request, which bypasses the standard permission mask check entirely when submitted by system_admin-level clients through CPM/DLE service (TCP 19009) under modern Check Point management architecture.

The resulting SSO ticket is obtained through a SOAP login call to the CPM service, which results in a fully authenticated SmartConsole session with clientSessionId and sid values that grant attackers the same privileges as legitimate administrators, including policy and configuration changes. Rapid7 has reported that exploitation requires network access to the Management Server and a default Trusted Clients setting that does not restrict GUI clients, a feature found to be enabled by default during testing. Organizations can detect potential exploit attempts by examining audit logs for the string "Authentication method: application token," which Rapid7 has identified as a reliable indicator of compromise related to ticket redemption steps.

By cutting off security investigation blind spots and containing threats earlier, organizations can reduce response costs and minimize business disruptions with ANY.RUN.