Multiple Check Point Products Integrity Clientless Security Security Bypass Vulnerability
BID:22233
Info
Multiple Check Point Products Integrity Clientless Security Security Bypass Vulnerability
| Bugtraq ID: | 22233 |
| Class: | Design Error |
| CVE: |
CVE-2007-0471 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 25 2007 12:00AM |
| Updated: | Mar 19 2015 08:36AM |
| Credit: | Roni Bachar and Nir Goldshlager are credited with the discovery of this vulnerability. |
| Vulnerable: |
Check Point Software VPN-1 Power/UTM Pro NGX R62 Check Point Software VPN-1 Power/UTM Pro NGX R61 Check Point Software VPN-1 Power/UTM Pro NGX R60 Check Point Software VPN-1 Power/UTM Pro NG AI R55W Check Point Software VPN-1 Power/UTM Pro NG AI R55 Check Point Software VPN-1 Power/UTM Express NGX R62 Check Point Software VPN-1 Power/UTM Express NGX R60 Check Point Software VPN-1 Power/UTM Express NG AI R55W Check Point Software VPN-1 Power/UTM Express NG AI R55 Check Point Software Connectra NGX R62 Check Point Software Connectra NGX R61 Check Point Software Connectra NGX R60 Check Point Software Connectra 2.0 Check Point VPN-1 Power/UTM Express NGX R61 |
| Not Vulnerable: | |
Discussion
Multiple Check Point Products Integrity Clientless Security Security Bypass Vulnerability
Multiple Check Point products are prone to a security-bypass vulnerability.
An attacker can exploit this issue to access cookie data and then use it to bypass certain security restrictions. This issue may potentially allow an attacker to gain unauthorized access to the affected application.
Multiple Check Point products are prone to a security-bypass vulnerability.
An attacker can exploit this issue to access cookie data and then use it to bypass certain security restrictions. This issue may potentially allow an attacker to gain unauthorized access to the affected application.
Exploit / POC
Multiple Check Point Products Integrity Clientless Security Security Bypass Vulnerability
Attackers may exploit this issue using a browser.
Attackers may exploit this issue using a browser.
Solution / Fix
Multiple Check Point Products Integrity Clientless Security Security Bypass Vulnerability
Solution:
The vendor released an advisory and various hotfixes to address this issue. Please see the references for more information.
Check Point Software Connectra 2.0
Check Point Software Connectra NGX R60
Check Point Software VPN-1 Power/UTM Express NG AI R55W
Check Point Software VPN-1 Power/UTM Pro NGX R61
Check Point Software Connectra NGX R62
Check Point Software Connectra NGX R61
Check Point Software VPN-1 Power/UTM Express NG AI R55
Check Point Software VPN-1 Power/UTM Pro NGX R62
Solution:
The vendor released an advisory and various hotfixes to address this issue. Please see the references for more information.
Check Point Software Connectra 2.0
-
Check Point ssl_HOTFIX2_2.0.tgz
http://www.checkpoint.com/techsupport/downloads/bin/connectra/v20/ssl_ HOTFIX2_2.0.tgz
Check Point Software Connectra NGX R60
-
Check Point security_HOTFIX5_R60.tgz
http://updates.checkpoint.com/fileserver/ID/7144/FILE/security_HOTFIX5 _R60.tgz
Check Point Software VPN-1 Power/UTM Express NG AI R55W
-
Check Point Software VPN-1_Hotfix1.pdf
http://updates.checkpoint.com/fileserver/ID/7126/FILE/VPN-1_Hotfix1.pd f
Check Point Software VPN-1 Power/UTM Pro NGX R61
-
Check Point Software http://updates.checkpoint.com/fileserver/ID/7122/FILE/vpn1_HOTFIX1_R61_windows.tgz
http://updates.checkpoint.com/fileserver/ID/7122/FILE/vpn1_HOTFIX1_R61 _windows.tgz
Check Point Software Connectra NGX R62
-
Check Point security_HOTFIX5_R62.tgz
http://updates.checkpoint.com/fileserver/ID/7142/FILE/security_HOTFIX5 _R62.tgz
Check Point Software Connectra NGX R61
-
Check Point security_HOTFIX5_R61.tgz
http://updates.checkpoint.com/fileserver/ID/7141/FILE/security_HOTFIX5 _R61.tgz
Check Point Software VPN-1 Power/UTM Express NG AI R55
-
Check Point vpn1_HOTFIX1_R62_windows.tgz
http://updates.checkpoint.com/fileserver/ID/7125/FILE/vpn1_HOTFIX1_R62 _windows.tgz
Check Point Software VPN-1 Power/UTM Pro NGX R62
-
Check Point vpn1_HOTFIX1_R62_windows.tgz
http://updates.checkpoint.com/fileserver/ID/7125/FILE/vpn1_HOTFIX1_R62 _windows.tgz -
Check Point Software VPN-1_Hotfix1.pdf
http://updates.checkpoint.com/fileserver/ID/7126/FILE/VPN-1_Hotfix1.pd f
References
Multiple Check Point Products Integrity Clientless Security Security Bypass Vulnerability
References:
References:
- [Full-disclosure] Check Point Connectra End Point security bypass (Roni Bacha)
- Check Point Software Homepage (Check Point Software)