cbcvebase.

Checkpoint Firewall-1 vulnerabilities

40 known vulnerabilities affecting checkpoint/firewall-1.

Total CVEs
40
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH19MEDIUM18LOW1

Vulnerabilities

Page 1 of 2
CVE-2004-0040P3CRITICALCVSS 10.0v4.1vnext_generation_fp0+1 more2004-03-03
CVE-2004-0040 [CRITICAL] CVE-2004-0040: Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemo Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.
nvd
CVE-2001-1303P4MEDIUMCVSS 5.0PoCv4.0v4.12001-07-18
CVE-2001-1303 [MEDIUM] CVE-2001-1303: The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configuration information for the protected network without authentication.
nvd
CVE-2000-0116P4HIGHCVSS 7.5PoCv3.02000-01-29
CVE-2000-0116 [HIGH] CVE-2000-0116: Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra < in front of the SCRIPT tag.
nvd
CVE-2001-0082P4HIGHCVSS 7.5PoCv4.12001-02-12
CVE-2001-0082 [HIGH] CVE-2001-0082: Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.
nvd
CVE-2000-1037P4HIGHCVSS 7.5PoCv3.0v4.0+1 more2000-12-11
CVE-2000-1037 [HIGH] CVE-2000-1037: Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack.
nvd
CVE-2003-0757P4MEDIUMCVSS 5.0PoCv4.0v4.12003-10-20
CVE-2003-0757 [MEDIUM] CVE-2003-0757: Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet.
nvd
CVE-2004-0469P3CRITICALCVSS 10.0v2.0v2.0.12004-07-07
CVE-2004-0469 [CRITICAL] CVE-2004-0469: Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG FP3 HFA-325, or VPN-1 SecuRemote/SecureClient R56, may allow remote attackers to execute arbitrary code during VPN tunnel negotiation.
nvd
CVE-2000-0582P4MEDIUMCVSS 5.0PoCv4.0v4.12000-06-30
CVE-2000-0582 [MEDIUM] CVE-2000-0582: Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros) to the SMTP Security Server proxy.
nvd
CVE-2000-0482P4MEDIUMCVSS 5.0PoCv4.0v4.12000-06-06
CVE-2000-0482 [MEDIUM] CVE-2000-0482: Check Point Firewall-1 allows remote attackers to cause a denial of service by sending a large numbe Check Point Firewall-1 allows remote attackers to cause a denial of service by sending a large number of malformed fragmented IP packets.
nvd
CVE-2004-0699P3HIGHCVSS 7.5v4.12004-09-28
CVE-2004-0699 [HIGH] CVE-2004-0699: Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by initiating an IKE negotiation and then sending an IKE packet with malformed ASN.1 data.
nvd
CVE-2001-0940P3HIGHCVSS 7.5v4.0v4.12001-09-21
CVE-2001-0940 [HIGH] CVE-2001-0940: Buffer overflow in the GUI authentication code of Check Point VPN-1/FireWall-1 Management Server 4.0 Buffer overflow in the GUI authentication code of Check Point VPN-1/FireWall-1 Management Server 4.0 and 4.1 allows remote attackers to execute arbitrary code via a long user name.
nvd
CVE-2000-0808P4HIGHCVSS 7.5v3.0v4.0+1 more2000-11-14
CVE-2000-0808 [HIGH] CVE-2000-0808: The seed generation mechanism in the inter-module S/Key authentication mechanism in Check Point VPN- The seed generation mechanism in the inter-module S/Key authentication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass authentication via a brute force attack, aka "One-time (s/key) Password Authentication."
nvd
CVE-2004-0079P4HIGHCVSS 7.5v2.0vnext_generation_fp0+2 more2004-11-23
CVE-2004-0079 [HIGH] CWE-476 CVE-2004-0079: The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
nvd
CVE-2000-0807P4HIGHCVSS 7.5v3.0v4.0+1 more2000-11-14
CVE-2000-0807 [HIGH] CVE-2000-0807: The OPSEC communications authentication mechanism (fwn1) in Check Point VPN-1/FireWall-1 4.1 and ear The OPSEC communications authentication mechanism (fwn1) in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to spoof connections, aka the "OPSEC Authentication Vulnerability."
nvd
CVE-2001-1158P4HIGHCVSS 7.5v4.1v4.1_build_414392001-07-09
CVE-2001-1158 [HIGH] CVE-2001-1158: Check Point VPN-1/FireWall-1 4.1 base.def contains a default macro, accept_fw1_rdp, which can allow Check Point VPN-1/FireWall-1 4.1 base.def contains a default macro, accept_fw1_rdp, which can allow remote attackers to bypass intended restrictions with forged RDP (internal protocol) headers to UDP port 259 of arbitrary hosts.
nvd
CVE-2001-1176P4HIGHCVSS 7.5v4.12001-07-12
CVE-2001-1176 [HIGH] CVE-2001-1176: Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewa Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via format strings in the control connection.
nvd
CVE-1999-0770P4LOWCVSS 2.1PoCv3.0v4.01999-07-29
CVE-1999-0770 [LOW] CVE-1999-0770: Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allo Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.
nvd
CVE-2000-0150P4HIGHCVSS 7.5v3.0v4.02000-02-12
CVE-2000-0150 [HIGH] CVE-2000-0150: Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server b Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.
nvd
CVE-2000-0804P4HIGHCVSS 7.5v3.0v4.0+1 more2000-11-14
CVE-2000-0804 [HIGH] CVE-2000-0804: Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass the directionality ch Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass the directionality check via fragmented TCP connection requests or reopening closed TCP connection requests, aka "One-way Connection Enforcement Bypass."
nvd
CVE-2002-0428P4HIGHCVSS 7.5v4.0v4.12002-08-12
CVE-2002-0428 [HIGH] CVE-2002-0428: Check Point FireWall-1 SecuRemote/SecuClient 4.0 and 4.1 allows clients to bypass the "authenticatio Check Point FireWall-1 SecuRemote/SecuClient 4.0 and 4.1 allows clients to bypass the "authentication timeout" by modifying the to_expire or expire values in the client's users.C configuration file.
nvd
Checkpoint Firewall-1 vulnerabilities | cvebase