CVE-2008-5849 describes an information disclosure vulnerability in Check Point VPN-1 R55, R65, and other versions when Port Address Translation (PAT) is enabled. Remote attackers can discover internal network IP addresses by sending a specially crafted packet with a low Time-To-Live (TTL) value, which causes the firewall to return an ICMP time-exceeded message containing an encapsulated intranet IP address. This vulnerability has a CVSS score of 5.0, indicating a medium severity, with low attack complexity and no authentication required, potentially leading to information disclosure but not impacting integrity or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
r55CPE matchmatch criteria | cpe:2.3:a:checkpoint:vpn-1:r55:*:*:*:*:*:*:* | ||
r65CPE matchmatch criteria | cpe:2.3:a:checkpoint:vpn-1:r65:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.