
Se ha identificado una vulnerabilidad crítica de tipo Stack Overflow (CWE-121) en el proceso de autenticación de los servidores de gestión de seguridad de Check Point. Un atacante remoto sin autenticación puede enviar un nombre de usuario excesivamente largo durante el proceso de login, causando un desbordamiento de pila que permite la ejecución de código arbitrario con privilegios root sin necesidad de credenciales válidas.
| CVE ID | CVE-2026-91843 |
| Descripción | Stack Overflow en proceso de login de Management Servers |
| Publicado | 16 de Septiembre, 2026 |
| CVSS v3.1 | 9.8 — CRÍTICA |
| Vector CVSS | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CWE Relacionado | CWE-121 (Stack-based Buffer Overflow) |
| Acceso | Red (sin autenticación previa) |
| Complejidad | Baja |
| Interacción Usuario | No requerida |
| Privilegios Requeridos | Ninguno |
| Estado de Explotación | Sin confirmación oficial (No en CISA KEV) |
| Advisory Oficial | sk1000155 (Check Point) |
| Procedimiento CPLP | sk185114 (Check Point Live Patch) |
PRODUCTOS Y VERSIONES AFECTADAS
| Producto | Versiones Vulnerables | Versión Corregida | Plataforma |
| Security Management Server | R82.20 todas R82.10 Take 44 o menor R82 Take 126 o menor R81.20 Take 166 o menor R81.10 Take 190 o menor (EoS) R80, R80.10-R80.40 (EoS) | R82.20 + Take 29 R82.10 Take 45+ R82 Take 127+ R81.20 Take 167+ Take 191+ Actualizar rama | Gaia |
| Multi-Domain Security Management Server | Igual a SMS | Igual a SMS | Gaia |
| Log Server | Igual a SMS | Igual a SMS | Gaia |
| Multi-Domain Log Server | Igual a SMS | Igual a SMS | Gaia |
Excepciones
| Producto | Status |
| Smart-1 Cloud | NO AFECTADO — Corrección ya implementada |
| Spark Firewall | NO AFECTADO |
Recomendaciones
- Aplicar LivePatch (CPLP) – Sin reinicio, protección inmediata
- Limitar Trusted Clients a IPs autorizadas – Bloquea acceso desde Internet
- Configurar reglas de Firewall perimetral – Protege Management Server
- Requerir VPN para acceso remoto – Capa adicional de seguridad
- Segmentación de red (VLAN administrativa) – Aislamiento del servidor
- Monitoreo y alertas en SIEM – Detectar intentos de ataque en tiempo real
Referencias
- https://support.checkpoint.com/results/sk/sk1000155
- https://support.checkpoint.com/results/sk/sk185114
- https://support.checkpoint.com/results/sk/sk175504
- https://support.checkpoint.com/results/sk/sk185102
- https://nvd.nist.gov/vuln/detail/CVE-2026-91843
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog<br> https://cwe.mitre.org/data/definitions/121.html
