PT-2009-1326 · Check Point · Check Point Vpn-1
Published
2009-01-06
·
Updated
2017-08-08
·
CVE-2008-5849
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Check Point VPN-1 versions R55, R65
Description
The issue allows remote attackers to discover intranet IP addresses when Port Address Translation (PAT) is used. This is achieved by sending a packet with a small TTL, which triggers an ICMP time exceeded in-transit response containing an encapsulated IP packet with an intranet address. For example, this can be demonstrated by sending a TCP packet to the firewall management server on port 18264.
Recommendations
For Check Point VPN-1 versions R55, R65, consider restricting access to the firewall management server on port 18264 as a temporary workaround until a patch is available.
Restrict the use of Port Address Translation (PAT) to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Check Point Vpn-1