Check Point confirmed worldwide exploitation of a pre-authentication VPN certificate flaw that reaches gateway code execution.
Check Point Security Gateway and Spark Firewall, VPN and firewall appliances deployed at enterprise and small-business network edges.
Unauthenticated code execution on a security gateway
Check Point confirmed worldwide exploitation attempts against a VPN certificate-validation flaw that permits pre-authentication gateway code execution. An attacker needs network reachability to the affected remote-access VPN negotiation service and does not need to authenticate.
Detail and 2 sources
The path requires network reachability to the affected remote-access VPN negotiation service but no authentication.
Check Point has published a fix, but pre-fix images remain accepted and complete revocation has not been established.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
- Reaches end-of-life hardware
- No
R81.10 later received a corrective Jumbo Hotfix, but affected R81 remains uncovered; therefore EOL coverage is only partial.