CVE-2024-24915

SmartConsole Sensitive Credential Exposure via Memory Dump

Severity
Medium 6.1
CVSS 3.1
Exploited
Not listed
EPSS
0.002
9.0th percentile
Discovered by
Not disclosed
Published
Jun 29, 2025
Assigned by checkpoint

Description

Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.

Weakness: CWE-316

Affected products

Vendor Product Category Matched by
Check Point SmartConsole Network & Security Management cna-assigner
Vendor-reported products (1)
  • checkpoint · Check Point SmartConsole

Something wrong here?