![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.80096 |
Category: | General |
Title: | Check Point VPN-1 PAT Information Disclosure Vulnerability - Active Check |
Summary: | Check Point VPN-1 PAT is prone to an information disclosure; vulnerability. |
Description: | Summary: Check Point VPN-1 PAT is prone to an information disclosure vulnerability. Vulnerability Insight: By sending crafted packets to ports on the firewall which are mapped by port address translation (PAT) to ports on internal devices, information about the internal network may be disclosed in the resulting ICMP error packets. Port 18264/tcp on the firewall is typically configured in such a manner, with packets to this port being rewritten to reach the firewall management server. For example, the firewall fails to correctly sanitise the encapsulated IP headers in ICMP time-to-live exceeded packets resulting in internal IP addresses being disclosed. False positive: This could be false positive alert. Try running same scan against single host where this vulnerability is reported. Solution: We are not aware of a vendor approved solution at the current time. On the following platforms, we recommend you mitigate in the described manner: - Checkpoint VPN-1 R55 - Checkpoint VPN-1 R65 We recommend you mitigate in the following manner: Disable any implied rules and only open ports for required services Filter outbound ICMP time-to-live exceeded packets. CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-5849 BugTraq ID: 32306 http://www.securityfocus.com/bid/32306 http://www.portcullis-security.com/293.php https://svn.wald.intevation.org/svn/openvas/trunk/openvas-plugins/scripts/checkpoint-vpn1-pat-information-disclosure.nasl http://secunia.com/advisories/32728 http://www.vupen.com/english/advisories/2008/3229 XForce ISS Database: vpn1-pat-information-disclosure(46645) https://exchange.xforce.ibmcloud.com/vulnerabilities/46645 |
Copyright | Copyright (C) 2008 Tim Brown and Portcullis Computer Security Ltd |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |