Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
By [email protected] (The Hacker News)
AI Summary
Check Point disclosed two critical vulnerabilities rated CVSS 9.8 in its Security Gateway firewall appliances and Security Management products, both related to VPN certificate handling and enabling unauthenticated remote code execution under unspecified 'specific conditions.' The vulnerabilities affect widely deployed Check Point perimeter security infrastructure, and the vendor's refusal to detail the triggering conditions limits defenders' ability to assess exposure. Organizations using Check Point Security Gateways should apply the available patches immediately given the RCE severity and unauthenticated attack vector.
Relevance score: 84.0/100
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →