CVE-2024-24915
29.06.2025, 12:15
Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.Enginsight
| Vendor | Product | Version |
|---|---|---|
| checkpoint | smartconsole | r81.10:build400 |
| checkpoint | smartconsole | r81.10:build402 |
| checkpoint | smartconsole | r81.10:build404 |
| checkpoint | smartconsole | r81.10:build406 |
| checkpoint | smartconsole | r81.10:build407 |
| checkpoint | smartconsole | r81.10:build409 |
| checkpoint | smartconsole | r81.10:build410 |
| checkpoint | smartconsole | r81.10:build412 |
| checkpoint | smartconsole | r81.10:build413 |
| checkpoint | smartconsole | r81.10:build414 |
| checkpoint | smartconsole | r81.10:build416 |
| checkpoint | smartconsole | r81.10:build417 |
| checkpoint | smartconsole | r81.10:build418 |
| checkpoint | smartconsole | r81.10:build420 |
| checkpoint | smartconsole | r81.10:build423 |
| checkpoint | smartconsole | r81.10:build424 |
| checkpoint | smartconsole | r81.10:build425 |
| checkpoint | smartconsole | r81.10:build426 |
| checkpoint | smartconsole | r81.10:build427 |
| checkpoint | smartconsole | r81.10:build428 |
| checkpoint | smartconsole | r81.10:build429 |
| checkpoint | smartconsole | r81.20:build640 |
| checkpoint | smartconsole | r81.20:build641 |
| checkpoint | smartconsole | r81.20:build645 |
| checkpoint | smartconsole | r81.20:build646 |
| checkpoint | smartconsole | r81.20:build649 |
| checkpoint | smartconsole | r81.20:build651 |
| checkpoint | smartconsole | r81.20:build653 |
| checkpoint | smartconsole | r81.20:build654 |
| checkpoint | smartconsole | r81.20:build655 |
| checkpoint | smartconsole | r81.20:build656 |
| checkpoint | smartconsole | r81.20:build658 |
| checkpoint | smartconsole | r81.20:build659 |
| checkpoint | smartconsole | r81.20:build660 |
| checkpoint | smartconsole | r81.20:build661 |
| checkpoint | smartconsole | r81.20:build663 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-316 - Cleartext Storage of Sensitive Information in MemoryThe application stores sensitive information in cleartext in memory.
- CWE-312 - Cleartext Storage of Sensitive InformationThe product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.