A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Checkpoint | Quantum Security Gateway | R81.10, R81, and R80.40, R81.20 with Jumbo Hotfix Take 141 or below, R82 with Jumbo Hotfix Take 103 or below, R82.10 with Jumbo Hotfix Take 19 or belowCNA affected | |
| Checkpoint | Spark Firewalls | R80.20.X, R81.10.X, and R82.00.XCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.