Vulnerability record · CVE-2002-1623 · published 31 December 2002
CVE-2002-1623: Check Point VPN-1 FireWall-1 IKE Aggressive Mode identity disclosure
Checkpoint · Vpn 1 Firewall 1
IKE Aggressive Mode with shared secret authentication does not encrypt initiator or responder identities during negotiation. This lets a remote party learn valid usernames by watching responses before the password is supplied or by sniffing the exchange, as originally reported for FireWall-1 SecuRemote.
Description
The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2) sniffing, as originally reported for FireWall-1 SecuRemote.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
medium priorityThe flaw is an information disclosure rated CVSS 5.0 with no KEV listing, but public exploit references and a high EPSS percentile raise the likelihood of attempted use.
What it is
IKE Aggressive Mode with shared secret authentication does not encrypt initiator or responder identities during negotiation. This lets a remote party learn valid usernames by watching responses before the password is supplied or by sniffing the exchange, as originally reported for FireWall-1 SecuRemote.
Impact
An attacker gains disclosure of valid usernames and identity information, which supports follow-on password guessing or targeted attacks. No integrity or availability impact is described.
Attack surface
Reachable over the network via IKE negotiation; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The flaw is inherent to the protocol design when Aggressive Mode is used with shared secret authentication.
Exploitation
Not listed in CISA KEV, but EPSS is 0.48573 (98.8th percentile) and two references are tagged Exploit, indicating public exploit material exists.
What to do
- Apply the vendor guidance in Check Point's IKE alert (checkpoint.com/techsupport/alerts/ike.html) or upgrade to a release that addresses the Aggressive Mode identity exposure.
- Disable IKE Aggressive Mode for shared secret authentication and use Main Mode where the environment permits.
- Move away from shared secret authentication toward certificate-based IKE authentication.
- Restrict IKE (UDP 500/4500) exposure to trusted source addresses and monitor for negotiation attempts from untrusted networks.
Detection
- Monitor IKE negotiation traffic for Aggressive Mode exchanges and log source addresses initiating them.
- Alert on repeated IKE negotiation attempts from a single source, which may indicate username enumeration.
- Correlate IKE negotiation logs with subsequent authentication failures for the same usernames.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-1623 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-1623), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.