Check Point VPN-1 SecureClient Policy Bypass Vulnerability
BID:15757
Info
Check Point VPN-1 SecureClient Policy Bypass Vulnerability
| Bugtraq ID: | 15757 |
| Class: | Race Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2005 12:00AM |
| Updated: | Dec 07 2005 12:00AM |
| Credit: | Viktor Steinmann <[email protected]> discovered this vulnerability. |
| Vulnerable: |
Check Point Software SecureClient NG with Application Intelligence R56 Check Point Software SecureClient NG FP1 Check Point Software SecureClient 4.1 Check Point Software SecureClient 4.0 |
| Not Vulnerable: | |
Discussion
Check Point VPN-1 SecureClient Policy Bypass Vulnerability
VPN-1 SecureClient is reported prone to a policy bypass vulnerability. This issue is due to a failure of the application to securely implement remote administrator-provided policies on affected computers.
This issue allows remote VPN users to bypass the administratively-defined security policies. Specific issues arising from this vulnerability depend on the intended policies defined by administrators. Some examples of the consequences are: unauthorized computers may connect, scripts may not execute, or insecure network configurations may be possible.
VPN-1 SecureClient is reported prone to a policy bypass vulnerability. This issue is due to a failure of the application to securely implement remote administrator-provided policies on affected computers.
This issue allows remote VPN users to bypass the administratively-defined security policies. Specific issues arising from this vulnerability depend on the intended policies defined by administrators. Some examples of the consequences are: unauthorized computers may connect, scripts may not execute, or insecure network configurations may be possible.
Exploit / POC
Check Point VPN-1 SecureClient Policy Bypass Vulnerability
An exploit is not required.
A sample script to overwrite the policy file is provided:
:Loop
copy x.scv local.scv
goto Loop
An exploit is not required.
A sample script to overwrite the policy file is provided:
:Loop
copy x.scv local.scv
goto Loop
Solution / Fix
Check Point VPN-1 SecureClient Policy Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Check Point VPN-1 SecureClient Policy Bypass Vulnerability
References:
References:
- VPN-1 Clients (Check Point Software)