Check Point Firewall-1 RDP Header Firewall Bypassing Vulnerability
BID:2952
Info
Check Point Firewall-1 RDP Header Firewall Bypassing Vulnerability
| Bugtraq ID: | 2952 |
| Class: | Configuration Error |
| CVE: |
CVE-2001-1158 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2001 12:00AM |
| Updated: | Jan 31 2019 06:00AM |
| Credit: | This vulnerability was originally discovered by Jochen Thomas Bauer <[email protected]> and Wesslowski <[email protected]>. |
| Vulnerable: |
Check Point Software Firewall-1 [ VPN + DES ] 4.1 Check Point Software Firewall-1 [ VPN + DES + STRONG ] 4.1 SP2 Build 41716 Check Point Software Firewall-1 [ VPN + DES + STRONG ] 4.1 Build 41439 Check Point Software Firewall-1 4.1 SP2 Check Point Software Firewall-1 4.1 |
| Not Vulnerable: | |
Discussion
Check Point Firewall-1 RDP Header Firewall Bypassing Vulnerability
Check Point Firewall-1 is an enterprise level, full feature firewall package distributed by Check Point. It is designed to work on various operating systems, both as a single firewall or as a firewall cluster system.
A problem has been discovered with the firewall that allows traversal. It is possible for a remote user to pass packets across the firewall via port 259 by using false RDP headers on UDP packets.
This makes it possible for remote users to gain access to restricted information systems.
Check Point Firewall-1 is an enterprise level, full feature firewall package distributed by Check Point. It is designed to work on various operating systems, both as a single firewall or as a firewall cluster system.
A problem has been discovered with the firewall that allows traversal. It is possible for a remote user to pass packets across the firewall via port 259 by using false RDP headers on UDP packets.
This makes it possible for remote users to gain access to restricted information systems.
Exploit / POC
Check Point Firewall-1 RDP Header Firewall Bypassing Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Check Point Firewall-1 RDP Header Firewall Bypassing Vulnerability
Solution:
Hotfixes are available for download from the Check Point Software Subscription Customer site:
Check Point Software Firewall-1 [ VPN + DES + STRONG ] 4.1 SP2 Build 41716
Check Point Software Firewall-1 [ VPN + DES + STRONG ] 4.1 Build 41439
Check Point Software Firewall-1 [ VPN + DES ] 4.1
Solution:
Hotfixes are available for download from the Check Point Software Subscription Customer site:
Check Point Software Firewall-1 [ VPN + DES + STRONG ] 4.1 SP2 Build 41716
Check Point Software Firewall-1 [ VPN + DES + STRONG ] 4.1 Build 41439
Check Point Software Firewall-1 [ VPN + DES ] 4.1
References
Check Point Firewall-1 RDP Header Firewall Bypassing Vulnerability
References:
References:
- Alerts - RDP (Check Point Software)
- Check Point Alerts (Check Point Software)
- Software Subscription Download Site (Check Point Software)