First published: Tue Nov 14 2000(Updated: )
Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass the directionality check via fragmented TCP connection requests or reopening closed TCP connection requests, aka "One-way Connection Enforcement Bypass."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Check Point FireWall-1 | =3.0 | |
Check Point FireWall-1 | =4.0 | |
Check Point FireWall-1 | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0804 is considered a critical vulnerability that allows remote attackers to bypass security checks in affected versions of Check Point VPN-1/FireWall-1.
To resolve CVE-2000-0804, upgrade to a later version of Check Point VPN-1/FireWall-1 that addresses this vulnerability.
CVE-2000-0804 affects Check Point VPN-1/FireWall-1 versions 3.0, 4.0, and 4.1.
Exploiting CVE-2000-0804 can allow attackers to bypass firewall restrictions, potentially leading to unauthorized access to sensitive network resources.
CVE-2000-0804 remains relevant for organizations still using the older versions of Check Point FireWall-1, which may still be vulnerable.