🔴 Critical: Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
-
Check Point has patched two critical vulnerabilities in how its firewall and management products handle VPN certificates. Both flaws carry a CVSS score of 9.8, and according to the company, they could allow an unauthenticated remote attacker to execute code — though only "under specific conditions" that Check Point has not disclosed.
The two issues are distinct in scope:
- One flaw affects Check Point Security Gateways, the company's firewall appliances.
- The second affects those same gateways as well as the Security Management side of the product line.
The article does not provide specific CVE identifiers for either vulnerability, so no advisory numbers are cited here. Administrators should refer to Check Point's official guidance for exact patch details and affected builds.
Because exploitation requires conditions Check Point has chosen not to describe, the practical risk is difficult to assess from the public disclosure alone. Even so, a 9.8 rating and unauthenticated RCE potential make prompt patching the sensible default for anyone running the affected gateway or management components.
Mitigation steps:
- Apply the vendor's patches for Security Gateways and Security Management as soon as possible.
- Verify which of your deployments fall into the affected product sets before assuming you are in the clear.
- Monitor vendor advisories for updated technical detail, since the triggering conditions remain undisclosed.
Source: The Hacker News
Are your Check Point gateways or management servers already patched against these two flaws?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login