CVE-2002-2405: Medium severity Checkpoint Firewall-1 vulnerability
Check Point FireWall-1 4.1 and Next Generation (NG), with UserAuth configured to proxy HTTP traffic only, allows remote attackers to pass unauthorized HTTPS, FTP and possibly other traffic through the firewall.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Reconfigure the Check Point FireWall-1 UserAuth settings so it is not configured to 'proxy HTTP traffic only'. Ensure UserAuth proxies/authenticates HTTPS, FTP and other relevant protocols (or remove the HTTP-only proxy restriction) to prevent unauthorized traffic from being passed through the firewall.
Check Point FireWall-1 UserAuth proxy mode = do not set to 'proxy HTTP traffic only' (ensure HTTPS, FTP and other protocols are proxied/authenticated)
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2405?
CVE-2002-2405 is considered to be a medium severity vulnerability due to its ability to allow unauthorized traffic through the firewall.
How do I fix CVE-2002-2405?
To fix CVE-2002-2405, ensure that UserAuth is configured properly to restrict HTTP traffic only and review firewall rules.
What versions of Check Point FireWall are affected by CVE-2002-2405?
CVE-2002-2405 affects Check Point FireWall-1 version 4.1 and the Next Generation (NG) version.
Can CVE-2002-2405 allow FTP traffic through the firewall?
Yes, CVE-2002-2405 can allow unauthorized FTP traffic through the firewall due to misconfiguration.
Who can exploit CVE-2002-2405?
Remote attackers can exploit CVE-2002-2405 if the firewall is not correctly configured to block unauthorized traffic.