// For flags

CVE-2008-1397

 

Severity Score

6.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Check Point VPN-1 Power/UTM, with NGX R60 through R65 and NG AI R55 software, allows remote authenticated users to cause a denial of service (site-to-site VPN tunnel outage), and possibly intercept network traffic, by configuring the local RFC1918 IP address to be the same as one of this tunnel's endpoint RFC1918 IP addresses, and then using SecuRemote to connect to a network interface at the other endpoint.

Check Point VPN-1 Power/UTM, con NGX R60 hasta R65 y el software NG AI R55, permite a usuarios remotos autenticados provocar una denegación de servicio (parada del túnel VPN sitio a sitio), y posiblemente interceptar tráfico de red, por la configuración de la dirección IP local RFC1918 al ser la misma que una de estas direcciones IP RFC1918 del punto final del túnel, y utilizando SecuRemote para conectar a una interfaz de red en el otro punto final.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-03-19 CVE Reserved
  • 2008-03-20 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Checkpoint
Search vendor "Checkpoint"
Check Point Vpn-1 Pro
Search vendor "Checkpoint" for product "Check Point Vpn-1 Pro"
ngx_r61
Search vendor "Checkpoint" for product "Check Point Vpn-1 Pro" and version "ngx_r61"
-
Affected
Checkpoint
Search vendor "Checkpoint"
Check Point Vpn-1 Pro
Search vendor "Checkpoint" for product "Check Point Vpn-1 Pro"
ngx_r62_ga
Search vendor "Checkpoint" for product "Check Point Vpn-1 Pro" and version "ngx_r62_ga"
-
Affected
Checkpoint
Search vendor "Checkpoint"
Vpn-1
Search vendor "Checkpoint" for product "Vpn-1"
ngx_r60
Search vendor "Checkpoint" for product "Vpn-1" and version "ngx_r60"
pro
Affected
Checkpoint
Search vendor "Checkpoint"
Vpn-1 Firewall-1
Search vendor "Checkpoint" for product "Vpn-1 Firewall-1"
ng_ai_r55
Search vendor "Checkpoint" for product "Vpn-1 Firewall-1" and version "ng_ai_r55"
-
Affected
Checkpoint
Search vendor "Checkpoint"
Vpn-1 Power Utm
Search vendor "Checkpoint" for product "Vpn-1 Power Utm"
ngx_r65_with_messaging_security
Search vendor "Checkpoint" for product "Vpn-1 Power Utm" and version "ngx_r65_with_messaging_security"
-
Affected
Checkpoint
Search vendor "Checkpoint"
Vpn-1 Power Utm With Ngx
Search vendor "Checkpoint" for product "Vpn-1 Power Utm With Ngx"
r65
Search vendor "Checkpoint" for product "Vpn-1 Power Utm With Ngx" and version "r65"
-
Affected