Global Recognition: Haris Floridis – The Cypriot security researcher who identified & disclosed a high-profile vulnerability in the company Checkpoint!!!
SecNews EXCLUSIVELY highlights today the discovery of a critical vulnerability in Checkpoint, a leading security company in the world, by a Cypriot researcher!

The weakness on the Checkpoint website
The exploitation of the vulnerability identified by Mr. Haris Floridis, as it turned out, provided the opportunity for an external malicious attacker, with zero knowledge of the company's internal infrastructure, to intercept or alter critical information. The use of the vulnerability, as reported by distinguished researchers contacted by SecNews, could cause incalculable consequences, exposing the company both in terms of confidentiality and legal issues with regard to its customers, but also, above all, to be a blow to the company's reputation.
The vulnerability was due to an incorrect parameter on the subpage where its partners around the world are displayed, specifically here (https://partners.us.checkpoint.com/partnerlocator/).
Partial exploitation of the vulnerability allowed the attacker to gain access to the Check Point Database with additional access expansion capabilities. The evidence of the existence & use of the vulnerability is in the possession of the Researcher and the company. The company confirms this access capability as shown in the relevant announcement, which however does not publish the exact details so as not to damage its reputation.
In addition, SecNews has information confirming the existence & use of the vulnerability, but does not make it public since it refers to the details of a Checkpoint customer on whom the tests were conducted.
Fully following the ethics of "Responsible Vulnerability Disclosure", Mr. Floridis communicated specific recommendations for its immediate resolution and proposals for additional investigation of possible incidents.
In a communication we sought with Mr. Haris Floridis, he told us that the identification of the extremely critical weakness was done without the use of automated tools, but manually. It is also known that penetration testers of high prestige and knowledge choose to use manual methods based exclusively on their knowledge background. Automated tools, moreover, make the identification and exploitation of weaknesses often impossible (due to the limited checks they perform).
SecNews would like to congratulate Mr. Haris Floridis for the extremely important discovery of the critical vulnerability and the exemplary handling of the responsible information he provided. However, congratulations also deserve Checkpoint for admitting the incident, publishing a press release to inform its customers, and immediately resolving the critical issue.



