CVE-2004-2679: High severity Checkpoint Firewall-1 vulnerability
Check Point Firewall-1 4.1 up to NG AI R55 allows remote attackers to obtain potentially sensitive information by sending an Internet Key Exchange (IKE) with a certain Vendor ID payload that causes Firewall-1 to return a response containing version and other information.
Affected Software
Event History
Frequently Asked Questions
What types of systems are affected by CVE-2004-2679?
CVE-2004-2679 affects Check Point FireWall-1 versions 4.0 and 4.1, including various service packs.
What kind of information can be exposed due to CVE-2004-2679?
CVE-2004-2679 may expose sensitive information such as version details and configuration data to remote attackers.
What is the severity level of CVE-2004-2679?
CVE-2004-2679 is considered a medium severity vulnerability due to the potential information disclosure.
How can I mitigate the risks associated with CVE-2004-2679?
To mitigate CVE-2004-2679, apply the latest patches or updates provided by Check Point for affected FireWall-1 versions.
Is there a workaround for CVE-2004-2679 if I can't apply a patch?
A potential workaround for CVE-2004-2679 is to restrict access to the firewall configuration interface to trusted IP addresses only.