CVE-2013-5635
Summary
| CVE | CVE-2013-5635 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-11-30 11:43:54 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not properly maintain the state of password failures, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by entering password guesses within multiple Unlock.exe processes that are running simultaneously. |
Risk And Classification
Primary CVSS: v2.0 3.3 from [email protected]
AV:L/AC:M/Au:N/C:P/I:P/A:N
EPSS: 0.000350000 probability, percentile 0.101870000 (date 2026-04-29)
Problem Types: CWE-255 | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:L/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Checkpoint | Endpoint Security | e80 | - | vpn_blade | All |
| Application | Checkpoint | Endpoint Security | e80.10 | - | vpn_blade | All |
| Application | Checkpoint | Endpoint Security | e80.20 | - | vpn_blade | All |
| Application | Checkpoint | Endpoint Security | e80.30 | - | vpn_blade | All |
| Application | Checkpoint | Endpoint Security | e80.40 | - | vpn_blade | All |
| Application | Checkpoint | Endpoint Security | e80.41 | - | vpn_blade | All |
| Application | Checkpoint | Endpoint Security | e80.50 | - | vpn_blade | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.digitalsec.net/stuff/explt+advs/CheckPoint_EndPoint_EPM_Explorer.txt | af854a3a-2127-422b-91ae-364da2661108 | www.digitalsec.net | |
| Check Point response to Media Encryption EPM Explorer lockout bypass (CVE-2013-5635 and CVE-2013-5636) | af854a3a-2127-422b-91ae-364da2661108 | supportcenter.checkpoint.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.