CVE-2007-0471: High severity CheckPoint Connectra Ngx vulnerability
sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authentication token.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0471?
CVE-2007-0471 is classified as a high severity vulnerability due to its ability to allow remote attackers to bypass security requirements.
How do I fix CVE-2007-0471?
To mitigate CVE-2007-0471, you must apply Security Hotfix 5 or later for Check Point Connectra NGX R62.
What components are affected by CVE-2007-0471?
CVE-2007-0471 affects the Integrity Clientless Security component in Check Point Connectra NGX R62 3.x and earlier.
What type of attack does CVE-2007-0471 enable?
CVE-2007-0471 enables remote attackers to craft a malicious Report parameter that returns a valid ICSCookie.
Which versions of Check Point Connectra are vulnerable to CVE-2007-0471?
Check Point Connectra NGX R62 and earlier versions are vulnerable to CVE-2007-0471, specifically those before Security Hotfix 5.