Firewall 1

Vendor:

First CVE: May 11, 1998 · Active for 28 years

43
Total CVEs
More Total CVEs than 97% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Firewall 1 over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 11, 1998
28 years ago
Most Recent CVE
Jul 27, 2006
7,303 days ago

CVE Severity & Scoring

Firewall 143 CVEs
All CVEs352,708 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (2.3%)
Unknown42 (97.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (2.3%)
High0 (0.0%)
Unknown42 (97.7%)
User Interaction
None1 (2.3%)
Unknown42 (97.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (2.3%)
Unknown42 (97.7%)

Top CVEs

Signals from CVEs in this product scope (43 CVEs).

43 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.
Feb 12, 20017.534NOYES
Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG FP3 HFA-325, or VPN-1 SecuRemot
Jul 7, 200410.032NONO
Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine
Dec 11, 20007.531NOYES
Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server
Mar 3, 200410.030NONO
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake t
Nov 23, 20047.529NONO
Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute ar
Mar 3, 200410.029NONO
Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, whi
Oct 20, 20035.028NOYES
Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra < in front of the SCRIPT tag.
Jan 29, 20007.528NOYES
The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configuration information for the protected network without authentic
Jul 18, 20015.026NOYES
Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros) to the SMTP Security Server p
Jun 30, 20005.025NOYES

Exploit Exposure

Signals from CVEs in this product scope (43 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
18.6% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (43 CVEs).

Media Mentions

Signals from CVEs in this product scope (43 CVEs).

Top CNAs Publishing CVEs For Firewall 1

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
r55w15.03.5%00
r5517.81.4%00
ng14.90.9%00
next_generation_fp235.89.1%00
next_generation_fp146.98.7%00
next_generation_fp046.98.7%00
4.1_build_4143917.53.2%00
4.1276.93.3%06
4.0246.82.1%06
3.0b17.20.4%00
3.0186.31.9%03
2.0.1110.05.0%00
2.046.98.0%00