CVE-2000-1032Checkpoint Firewall-1 vulnerability

3 documents3 sources
Severity
5.0MEDIUMNVD
EPSS
1.2%
top 21.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateApr 30

Description

The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDcheckpoint/firewall-13.0, 4.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2pf5-35fc-x4fg: The client authentication interface for Check Point Firewall-1 42022-04-30
CVEList
CVE-2000-1032: The client authentication interface for Check Point Firewall-1 42001-01-22