important · RCE — VPN
Check Point says attackers are exploiting its pre-authentication VPN certificate RCE against Spark gateways.
Affects
Check Point Security Gateway and Spark Firewall, embedded network-security appliances providing firewall and VPN services.
Malicious certificate data supplied during VPN negotiation can execute code before authentication in the gateway service context.
Detail and 1 source
The exact fixed hotfix and build matrix could not be confirmed from the available record.