Check Point VPN gateways need urgent updates
Check Point VPN gateways are critical security tools that let remote workers safely connect to company networks. Two newly fixed flaws could let attackers bypass your VPN's security and access your network directly, even if you have a strong password.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Not confirmed
- Affects
- Check Point
- Exploited
- Not confirmedNo confirmation recorded
How it works
- The first flaw lets attackers send a specially crafted VPN connection request that tricks the gateway into accepting it without proper checks.
- The second flaw lets attackers send a malformed VPN packet that crashes the gateway's VPN service, stopping remote access until it's restarted.
- Both flaws require no user interaction and can be exploited remotely by attackers who know your VPN's address.
What to do
If you run Check Point Security Gateway R80.40 or R81, check your installed version by opening the Management Console and navigating to System > Overview. Compare it against the advisory for the exact fixed release.
Update to Check Point Security Gateway R80.40 Take-290 or R81.30 or later immediately. Restart the VPN service after updating. Check the Management Console after updating to confirm the new version is active.
Technical details
Check Point fixed two 9.8-severity VPN flaws before any known exploitation in the wild.