CVE-2005-4093
Summary
| CVE | CVE-2005-4093 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-12-08 11:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modifying the local copy of the local.scv policy file after it has been downloaded from the VPN Endpoint. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Checkpoint | Secureclient Ng | All | All | fp1 | All |
| Application | Checkpoint | Secureclient Ng | r56 | All | All | All |
| Application | Checkpoint | Vpn-1 Secureclient | 4.0 | All | All | All |
| Application | Checkpoint | Vpn-1 Secureclient | 4.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Check Point VPN-1 SecureClient Lets Local Users Bypass Security Policy | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| [Full-disclosure] Checkpoint SecureClient NGX Security Policy can easily be disabled | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| Secunia - Advisories - Check Point VPN-1 SecureClient Secure Configuration Verification Bypass Weakness | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Re: [swinog] Checkpoint Flaw | af854a3a-2127-422b-91ae-364da2661108 | www.mail-archive.com | |
| [swinog] Checkpoint Flaw | af854a3a-2127-422b-91ae-364da2661108 | www.mail-archive.com | |
| Check Point VPN-1 SecureClient Policy Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Debian update for kernel-source-2.4.27 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1237-1 kernel-source-2.4.27 | af854a3a-2127-422b-91ae-364da2661108 | www.us.debian.org | |
| [swinog] Checkpoint Flaw | MITRE | www.mail-archive.com | |
| Re: [swinog] Checkpoint Flaw | MITRE | www.mail-archive.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.