Vpn 1
Vendor:
First CVE: Jul 12, 2001 · Active for 25 years
14
Total CVEs
More Total CVEs than 91% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vpn 1 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 12, 2001
25 years ago
Most Recent CVE
Oct 5, 2011
5,409 days ago
CVE Severity & Scoring
Vpn 114 CVEs
43%
57%
All CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (7.1%)
Unknown13 (92.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (7.1%)
High0 (0.0%)
Unknown13 (92.9%)
User Interaction
None1 (7.1%)
Unknown13 (92.9%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (7.1%)
Unknown13 (92.9%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0469HIGH Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG FP3 HFA-325, or VPN-1 SecuRemot | Jul 7, 2004 | 10.0 | 32 | NO | NO |
CVE-2004-0079HIGH The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake t | Nov 23, 2004 | 7.5 | 29 | NO | NO |
CVE-2004-0040HIGH Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute ar | Mar 3, 2004 | 10.0 | 29 | NO | NO |
CVE-2011-1827HIGH Multiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distributed by SecurePlatform, IPSO6, Connectra | Oct 5, 2011 | 9.3 | 28 | NO | NO |
CVE-2004-0112MEDIUM The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, whi | Nov 23, 2004 | 5.0 | 23 | NO | NO |
CVE-2005-3673HIGH The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstr | Nov 18, 2005 | 7.8 | 21 | NO | NO |
CVE-2004-0699HIGH Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by in | Sep 28, 2004 | 7.5 | 21 | NO | NO |
CVE-2008-1397MEDIUM Check Point VPN-1 Power/UTM, with NGX R60 through R65 and NG AI R55 software, allows remote authenticated users to cause a denial of service (site-to-site VPN tunnel outage), and p | Mar 20, 2008 | 6.5 | 20 | NO | NO |
CVE-2001-1176HIGH Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via format strings in the control con | Jul 12, 2001 | 7.5 | 20 | NO | NO |
CVE-2001-1499MEDIUM Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, wh | Dec 31, 2001 | 5.0 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Vpn 1
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| vsx_ng_with_application_intelligence | 4 | 6.9 | 8.0% | 0 | 0 |
| vsx_2.0.1 | 1 | 10.0 | 5.0% | 0 | 0 |
| r75 | 1 | 9.3 | 4.5% | 0 | 0 |
| r71.30 | 1 | 9.3 | 4.5% | 0 | 0 |
| r70.40 | 1 | 9.3 | 4.5% | 0 | 0 |
| r65.70 | 1 | 9.3 | 4.5% | 0 | 0 |
| r65 | 1 | 5.0 | 1.6% | 0 | 0 |
| r55 | 1 | 5.0 | 1.6% | 0 | 0 |
| ngx_r60 | 2 | 7.2 | 3.5% | 0 | 0 |
| next_generation_fp2 | 2 | 6.3 | 10.0% | 0 | 0 |
| next_generation_fp1 | 4 | 6.9 | 8.7% | 0 | 0 |
| next_generation_fp0 | 4 | 6.9 | 8.7% | 0 | 0 |
| next_generation | 1 | 5.0 | 7.2% | 0 | 0 |
| 4.1 | 5 | 7.0 | 1.5% | 0 | 0 |