PT-2000-1947 · Check Point · Check Point Firewall-1

Published

2000-12-11

·

Updated

2008-09-05

·

CVE-2000-1037

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Check Point Firewall-1 session agent versions 3.0 through 4.1
Description The issue allows remote attackers to determine valid usernames and guess a password via a brute force attack, due to different error messages being generated for invalid user names versus invalid passwords.
Recommendations For versions 3.0 through 4.1, consider modifying the error message handling to prevent disclosure of valid usernames, and implement additional security measures such as account lockout policies or rate limiting to mitigate the risk of brute force attacks.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-1037

Affected Products

Check Point Firewall-1