CVE-1999-0770: Low severity checkpoint firewall-1 vulnerability
Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Reduce the connection timeout for ACK/other non-SYN initiated connections in the firewall configuration to a shorter duration so the device does not retain large numbers of incomplete connections and become susceptible to denial-of-service from many connection attempts to unresponsive systems.
Check Point FireWall-1 timeout for connections that begin with ACK or non-SYN packets = reduce timeout (shorter duration)
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0770?
CVE-1999-0770 is considered a high severity vulnerability due to its ability to allow denial of service attacks.
How do I fix CVE-1999-0770?
To mitigate CVE-1999-0770, update your Check Point FireWall-1 software to a patched version that addresses this vulnerability.
What software versions are affected by CVE-1999-0770?
CVE-1999-0770 affects Check Point FireWall-1 versions 3.0 and 4.0.
What type of attack can be performed using CVE-1999-0770?
An attacker can exploit CVE-1999-0770 to launch a denial of service attack by overwhelming the firewall with connection attempts.
Is CVE-1999-0770 still relevant today?
While CVE-1999-0770 was identified over two decades ago, it remains relevant for legacy systems that have not been updated.