Check Point VPN-1 IP Address Collision Denial of Service Vulnerability
BID:28299
Info
Check Point VPN-1 IP Address Collision Denial of Service Vulnerability
| Bugtraq ID: | 28299 |
| Class: | Design Error |
| CVE: |
CVE-2008-1397 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Robert Mitchell <[email protected]> of PureSecurity discovered this issue and acknowledges the aid of Mitchell Woodward, acknowledges Michael Kapelevich and the Check Point Security Alert team. |
| Vulnerable: |
Check Point Software VPN-1 Power/UTM NGX R65 Check Point Software VPN-1 Power/UTM NGX R62 Check Point Software VPN-1 Power/UTM NGX R61 Check Point Software VPN-1 Power/UTM NGX R60 |
| Not Vulnerable: | |
Discussion
Check Point VPN-1 IP Address Collision Denial of Service Vulnerability
Check Point VPN-1 is prone to a denial-of-service vulnerability that can allow attackers to obtain sensitive information. The issue occurs because the application fails to adequately handle IP address collisions.
Attackers can exploit this issue to break site-to-site VPN connectivity between a VPN-1 gateway and a third party, denying access to legitimate users. If SecuRemote back-connections are enabled, the attacker can leverage this issue to re-route site-to-site VPN traffic from the VPN gateway to their SecuRemote client. Under certain conditions, this will cause data that was destined for the third party to be sent to the attacker's client instead. This could contain sensitive information that would aid in further attacks.
Check Point VPN-1 is prone to a denial-of-service vulnerability that can allow attackers to obtain sensitive information. The issue occurs because the application fails to adequately handle IP address collisions.
Attackers can exploit this issue to break site-to-site VPN connectivity between a VPN-1 gateway and a third party, denying access to legitimate users. If SecuRemote back-connections are enabled, the attacker can leverage this issue to re-route site-to-site VPN traffic from the VPN gateway to their SecuRemote client. Under certain conditions, this will cause data that was destined for the third party to be sent to the attacker's client instead. This could contain sensitive information that would aid in further attacks.
Exploit / POC
Check Point VPN-1 IP Address Collision Denial of Service Vulnerability
Attackers can exploit this issue via a SecuRemote client.
Proof-of-concept information is available in the following document:
http://www.puresecurity.com.au/files/PureSecurity%20VPN-1%20DoS_Spoofing%20Attack%20against%20VPN%20tunnels.pdf
Attackers can exploit this issue via a SecuRemote client.
Proof-of-concept information is available in the following document:
http://www.puresecurity.com.au/files/PureSecurity%20VPN-1%20DoS_Spoofing%20Attack%20against%20VPN%20tunnels.pdf
Solution / Fix
Check Point VPN-1 IP Address Collision Denial of Service Vulnerability
Solution:
The vendor released a hotfix to address this issue. Please the references and contact the vendor for information on obtaining and applying the fix.
Solution:
The vendor released a hotfix to address this issue. Please the references and contact the vendor for information on obtaining and applying the fix.
References
Check Point VPN-1 IP Address Collision Denial of Service Vulnerability
References:
References:
- Vendor Homepage (Check Point Software)
- VPN-1 NGX R65 HFA_02 Supplement 3 (Check Point Software)
- Check Point VPN-1 SecuRemote DoS/Spoofing Attack for Site-Site VPN (PureSecurity)
- Vulnerability Note VU#992585 Check Point VPN-1 information disclosure vulnerabil (US-CERT)