This vulnerability affects Check Point SmartConsole instances that are directly exposed to the internet without restrictions on who can connect. In those specific circumstances, Check Point says an attacker may be able to bypass the normal sign-in process.
It gives me flashbacks to the CrowdStrike incident where people were asking how a security product could lead to the exact scenario it's trying to prevent.
Some important points to consider:
- Are any security management systems reachable from the public internet?
- Are the right access controls in place to prevent unauthorised access?
- When a vendor alert is issued, can you identify affected systems, apply the fix and report completion promptly?

