CVE-2000-1037 describes an information leakage vulnerability in Check Point Firewall-1 session agent versions 3.0 through 4.1. The flaw allows remote attackers to differentiate between invalid usernames and invalid passwords based on distinct error messages, facilitating username enumeration and subsequent brute-force password guessing. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating that it is network-exploitable with low attack complexity, potentially leading to partial compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, exploit code for dictionary attacks against this vulnerability is publicly available on ExploitDB. There is no evidence of active exploitation, nor significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:checkpoint:firewall-1:3.0:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:checkpoint:firewall-1:4.0:*:*:*:*:*:*:* | ||
4.1CPE matchmatch criteria | cpe:2.3:a:checkpoint:firewall-1:4.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.