|
Check Point Products ICS Security Bypass
|
|
Secunia Advisory:
|
SA23847
|
|
|
Release Date:
|
2007-01-25
|
|
Popularity:
|
7,319 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Security Bypass
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Check Point Connectra Appliances
|
|
| Software: | Check Point VPN-1 Power NG AI Check Point VPN-1 Power NGX Check Point VPN-1 UTM NG AI Check Point VPN-1 UTM NGX
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: Roni Bachar and Nir Goldshlager have reported a vulnerability in Check Point products, which can be exploited by malicious people to bypass certain security restrictions.
The problem is that /sre/params.php in ICS (Integrity Clientless Security) does not properly validate the data being sent to it. This can be exploited to receive a cookie, which can be used to bypass certain checks before being allowed to log in to the network, by sending a POST request with a valid report to the /sre/params.php page.
Successful exploitation requires that the ICS feature is enabled.
The vulnerability affects the following products and versions:
* Connectra NGX R62
* Connectra NGX R61
* Connectra NGX R60
* Connectra 2.0
* VPN-1 Power/UTM (Pro/Express) NGX R62
* VPN-1 Power/UTM (Pro/Express) NGX R61
* VPN-1 Power/UTM (Pro/Express) NGX R60
* VPN-1 Power/UTM (Pro/Express) NG AI R55W
* VPN-1 Power/UTM (Pro/Express) NG AI R55
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|