Unauthenticated or authenticated packet flow parsing flaw allows shell escape into underlying Linux GAiA kernel context.
Exposed ports 443 / 19009 allow traversal through management service handlers when exposed beyond dedicated isolation rings.
Exploited service worker executes with UID 0 (`root`), bypassing clish shell restrictions and granting full filesystem persistence.
Apply immediate security update from Check Point advisory
Download and deploy the security hotfix via CPUSE (Gaia Deployment Agent) to neutralise the root execution flaw.
Enforce strict GUI Clients access list to prevent unauthorized inbound connections from untrusted networks.
Inspect system audit logs for indicators of compromise (IOCs) such as suspicious `/bin/bash` or `clish` spawns.