Checkpoint

Quantum Security Gateway

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 09.09.2026 13:00:42
  • Zuletzt bearbeitet 10.09.2026 04:18:18

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

Warnung Medienbericht
  • EPSS 0.33%
  • Veröffentlicht 09.09.2026 13:00:31
  • Zuletzt bearbeitet 23.09.2026 18:22:07

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Medienbericht
  • EPSS 0.39%
  • Veröffentlicht 22.07.2026 13:53:53
  • Zuletzt bearbeitet 24.07.2026 05:16:45

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

Warnung Medienbericht
  • EPSS 82.55%
  • Veröffentlicht 08.06.2026 11:07:15
  • Zuletzt bearbeitet 04.08.2026 05:16:39

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user...

Medienbericht
  • EPSS 4.55%
  • Veröffentlicht 08.06.2026 11:00:38
  • Zuletzt bearbeitet 23.07.2026 07:10:00

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based au...

  • EPSS 2.61%
  • Veröffentlicht 26.05.2026 12:57:19
  • Zuletzt bearbeitet 24.07.2026 11:10:00

A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation.

Medienbericht
  • EPSS 4.36%
  • Veröffentlicht 26.05.2026 12:57:07
  • Zuletzt bearbeitet 24.07.2026 11:10:00

When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserC...

Medienbericht
  • EPSS 4.75%
  • Veröffentlicht 26.05.2026 12:56:56
  • Zuletzt bearbeitet 24.07.2026 11:10:00

When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.

Medienbericht
  • EPSS 2.14%
  • Veröffentlicht 26.05.2026 12:56:47
  • Zuletzt bearbeitet 24.07.2026 11:10:00

The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to deni...

Medienbericht
  • EPSS 2.66%
  • Veröffentlicht 26.05.2026 12:56:08
  • Zuletzt bearbeitet 24.07.2026 11:10:00

The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption...