CVE-2008-1397 describes a denial-of-service vulnerability affecting Check Point VPN-1 Power/UTM and NGX R60-R65/NG AI R55 software. An authenticated remote attacker can trigger a site-to-site VPN tunnel outage and potentially intercept network traffic by misconfiguring local RFC1918 IP addresses to conflict with tunnel endpoints. This vulnerability has a CVSS score of 6.5, indicating medium severity, with low attack complexity and potential for partial confidentiality, integrity, and availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
ngx_r61CPE matchmatch criteria | cpe:2.3:a:checkpoint:check_point_vpn-1_pro:ngx_r61:*:*:*:*:*:*:* | ||
ngx_r62_gaCPE matchmatch criteria | cpe:2.3:a:checkpoint:check_point_vpn-1_pro:ngx_r62_ga:*:*:*:*:*:*:* | ||
ngx_r60CPE matchmatch criteria | cpe:2.3:a:checkpoint:vpn-1:ngx_r60:*:pro:*:*:*:*:* | ||
ng_ai_r55CPE matchmatch criteria | cpe:2.3:a:checkpoint:vpn-1_firewall-1:ng_ai_r55:*:*:*:*:*:*:* | ||
ngx_r65_with_messaging_securityCPE matchmatch criteria | cpe:2.3:a:checkpoint:vpn-1_power_utm:ngx_r65_with_messaging_security:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.