PT-2014-2012 · Check Point · Check Point R75.47 Security Gateway+1

Publicado

2014-01-14

·

Atualizado

2018-01-03

·

CVE-2014-1672

CVSS v2.0

4.0

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Check Point R75.47 Security Gateway and Management Server
Description The issue is related to a lack of proper enforcement of Anti-Spoofing when the routing table is modified and the "Get - Interfaces with Topology" action is performed. This allows attackers to bypass intended access restrictions. The vulnerability is also associated with insufficient access control to certain features, which can be exploited by a remote attacker to bypass existing access restrictions and conduct spoofing attacks.
Recommendations For Check Point R75.47 Security Gateway and Management Server, consider restricting access to the "Get - Interfaces with Topology" action until a patch is available. As a temporary workaround, review and modify the routing table configuration to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-03759
CVE-2014-1672

Produtos afetados

Check Point R75.47 Management Server
Check Point R75.47 Security Gateway