Generic HTTP Command Injection (CVE-2022-28491; CVE-2022-28495; CVE-2022-40847; CVE-2023-1457; CVE-2023-1458; CVE-2023-24154; CVE-2023-24159; CVE-2023-31569; CVE-2023-31856; CVE-2023-33486; CVE-2023-36457; CVE-2023-38862; CVE-2023-38863; CVE-2023-38864)

Check Point Reference: CPAI-2023-0686 Date Published: 29 Aug 2023 Severity: Critical Last Updated: Sunday 26 November, 2023 Source: Industry Reference:CVE-2022-28491
CVE-2022-28495
CVE-2022-40847
CVE-2023-1457
CVE-2023-1458
CVE-2023-24154
CVE-2023-24159
CVE-2023-31569
CVE-2023-31856
CVE-2023-33486
CVE-2023-36457
CVE-2023-38862
CVE-2023-38863
CVE-2023-38864
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? Vulnerability Description A generic HTTP command injection vulnerability has been reported. A remote attacker can exploit this issue by sending a specially crafted request to the victim. Successful exploitation would allow an attacker to execute arbitrary code on the target machine.