CVE-2008-1397
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Check Point VPN-1 Power/UTM, with NGX R60 through R65 and NG AI R55 software, allows remote authenticated users to cause a denial of service (site-to-site VPN tunnel outage), and possibly intercept network traffic, by configuring the local RFC1918 IP address to be the same as one of this tunnel's endpoint RFC1918 IP addresses, and then using SecuRemote to connect to a network interface at the other endpoint.
Check Point VPN-1 Power/UTM, con NGX R60 hasta R65 y el software NG AI R55, permite a usuarios remotos autenticados provocar una denegación de servicio (parada del túnel VPN sitio a sitio), y posiblemente interceptar tráfico de red, por la configuración de la dirección IP local RFC1918 al ser la misma que una de estas direcciones IP RFC1918 del punto final del túnel, y utilizando SecuRemote para conectar a una interfaz de red en el otro punto final.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-03-19 CVE Reserved
- 2008-03-20 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://puresecurity.com.au/index.php?action=fullnews&id=5 | X_refsource_misc | |
http://www.kb.cert.org/vuls/id/992585 | Third Party Advisory | |
http://www.securityfocus.com/bid/28299 | Vdb Entry | |
http://www.securitytracker.com/id?1019666 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/0953/references | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41260 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://www.puresecurity.com.au/files/PureSecurity%20VPN-1%20DoS_Spoofing%20Attack%20against%20VPN%20tunnels.pdf | 2024-08-07 |
URL | Date | SRC |
---|---|---|
https://supportcenter.checkpoint.com/supportcenter/portal?solutionid=sk34579 | 2017-08-08 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/29394 | 2017-08-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Checkpoint Search vendor "Checkpoint" | Check Point Vpn-1 Pro Search vendor "Checkpoint" for product "Check Point Vpn-1 Pro" | ngx_r61 Search vendor "Checkpoint" for product "Check Point Vpn-1 Pro" and version "ngx_r61" | - |
Affected
| ||||||
Checkpoint Search vendor "Checkpoint" | Check Point Vpn-1 Pro Search vendor "Checkpoint" for product "Check Point Vpn-1 Pro" | ngx_r62_ga Search vendor "Checkpoint" for product "Check Point Vpn-1 Pro" and version "ngx_r62_ga" | - |
Affected
| ||||||
Checkpoint Search vendor "Checkpoint" | Vpn-1 Search vendor "Checkpoint" for product "Vpn-1" | ngx_r60 Search vendor "Checkpoint" for product "Vpn-1" and version "ngx_r60" | pro |
Affected
| ||||||
Checkpoint Search vendor "Checkpoint" | Vpn-1 Firewall-1 Search vendor "Checkpoint" for product "Vpn-1 Firewall-1" | ng_ai_r55 Search vendor "Checkpoint" for product "Vpn-1 Firewall-1" and version "ng_ai_r55" | - |
Affected
| ||||||
Checkpoint Search vendor "Checkpoint" | Vpn-1 Power Utm Search vendor "Checkpoint" for product "Vpn-1 Power Utm" | ngx_r65_with_messaging_security Search vendor "Checkpoint" for product "Vpn-1 Power Utm" and version "ngx_r65_with_messaging_security" | - |
Affected
| ||||||
Checkpoint Search vendor "Checkpoint" | Vpn-1 Power Utm With Ngx Search vendor "Checkpoint" for product "Vpn-1 Power Utm With Ngx" | r65 Search vendor "Checkpoint" for product "Vpn-1 Power Utm With Ngx" and version "r65" | - |
Affected
|