← Vulnerability feed

Vulnerability record · CVE-2000-0150 · published 12 February 2000

CVE-2000-0150: Checkpoint firewall-1 vulnerability

Checkpoint · Firewall 1

Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.

7.5 CVSS 2.0 High EPSS 2.2% · top 18.1%
7.5CVSS 2.0 base score
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-0150 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed10.0CVE-2004-0469Checkpoint firewall-1 vulnerabilityBuffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG …EPSS 5.0%10.0CVE-2004-0039Checkpoint firewall-1 vulnerabilityMultiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point F…EPSS 9.3%10.0CVE-2004-0040Checkpoint firewall-1 vulnerabilityStack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows…EPSS 7.6%9.0CVE-2007-0960Cisco asa 5500 vulnerabilityUnspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, all…EPSS 2.6%7.8CVE-2007-0961Cisco asa 5500 vulnerabilityCisco PIX 500 and ASA 5500 Series Security Appliances 6.x before 6.3(5.115), 7.0 before 7.0(5.2), and 7.1 before 7.1(2.5), and the FWSM 3.x before 3.…EPSS 3.3%7.8CVE-2007-0959Cisco asa 5500 vulnerabilityCisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause…EPSS 2.4%7.8CVE-2007-0962Cisco firewall services module vulnerabilityCisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before …EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2000-0150), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.