PT-2007-1936 · Check Point · Check Point Vpn-1 Ngx R62+2
Nir Goldshlager
+1
·
Publicado
2007-01-24
·
Atualizado
2018-10-16
·
CVE-2007-0471
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Check Point Connectra NGX R62 versions 3.x and earlier before Security Hotfix 5
Check Point VPN-1 NGX R62 (affected versions not specified)
Description
The issue allows remote attackers to bypass security requirements. This is achieved by sending a crafted Report parameter to the sre/params.php file in the Integrity Clientless Security (ICS) component, which then returns a valid ICSCookie authentication token.
Recommendations
For Check Point Connectra NGX R62 versions 3.x and earlier, apply Security Hotfix 5 to resolve the issue.
For Check Point VPN-1 NGX R62, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Check Point Connectra Ngx R62
Check Point Vpn-1 Ngx R62
Integrity Clientless Security