CVE-2001-1431: Medium severity Checkpoint Firewall-1 vulnerability
Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWall-1 4.1 Service Pack 3, IPSO 3.4 and VPN-1/FireWall-1 4.1 Service Pack 4, and IPSO 3.4 or IPSO 3.4.1 and VPN-1/FireWall-1 4.1 Service Pack 5, when SYN Defender is configured in Active Gateway mode, does not properly rewrite the third packet of a TCP three-way handshake to use the NAT IP address, which allows remote attackers to gain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1431?
CVE-2001-1431 has a medium severity rating due to the potential for denial of service attacks.
How do I mitigate CVE-2001-1431?
To mitigate CVE-2001-1431, upgrade to the latest patched versions of Check Point FireWall-1 and VPN-1 that address this issue.
Which systems are affected by CVE-2001-1431?
CVE-2001-1431 affects Nokia Firewall Appliances running specific versions of IPSO and Check Point firewall software.
What is the main issue described in CVE-2001-1431?
The main issue in CVE-2001-1431 is that SYN Defender does not rewrite the third packet correctly when configured in Active Gateway mode.
Is there a workaround for CVE-2001-1431?
There is no widely recommended workaround for CVE-2001-1431, making updates the best approach.