PT-2007-1936 · Check Point · Check Point Vpn-1 Ngx R62+2

Nir Goldshlager

+1

·

Published

2007-01-24

·

Updated

2018-10-16

·

CVE-2007-0471

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Check Point Connectra NGX R62 versions 3.x and earlier before Security Hotfix 5 Check Point VPN-1 NGX R62 (affected versions not specified)
Description The issue allows remote attackers to bypass security requirements. This is achieved by sending a crafted Report parameter to the sre/params.php file in the Integrity Clientless Security (ICS) component, which then returns a valid ICSCookie authentication token.
Recommendations For Check Point Connectra NGX R62 versions 3.x and earlier, apply Security Hotfix 5 to resolve the issue. For Check Point VPN-1 NGX R62, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-0471

Affected Products

Check Point Connectra Ngx R62
Check Point Vpn-1 Ngx R62
Integrity Clientless Security