← Vulnerability feed

Vulnerability record · CVE-2002-1623 · published 31 December 2002

CVE-2002-1623: Check Point VPN-1 FireWall-1 IKE Aggressive Mode identity disclosure

Checkpoint · Vpn 1 Firewall 1

IKE Aggressive Mode with shared secret authentication does not encrypt initiator or responder identities during negotiation. This lets a remote party learn valid usernames by watching responses before the password is supplied or by sniffing the exchange, as originally reported for FireWall-1 SecuRemote.

5.0 CVSS 2.0 Medium EPSS 49% · top 1.2%
5.0CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2) sniffing, as originally reported for FireWall-1 SecuRemote.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityThe flaw is an information disclosure rated CVSS 5.0 with no KEV listing, but public exploit references and a high EPSS percentile raise the likelihood of attempted use.

What it is

IKE Aggressive Mode with shared secret authentication does not encrypt initiator or responder identities during negotiation. This lets a remote party learn valid usernames by watching responses before the password is supplied or by sniffing the exchange, as originally reported for FireWall-1 SecuRemote.

Impact

An attacker gains disclosure of valid usernames and identity information, which supports follow-on password guessing or targeted attacks. No integrity or availability impact is described.

Attack surface

Reachable over the network via IKE negotiation; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The flaw is inherent to the protocol design when Aggressive Mode is used with shared secret authentication.

Exploitation

Not listed in CISA KEV, but EPSS is 0.48573 (98.8th percentile) and two references are tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the vendor guidance in Check Point's IKE alert (checkpoint.com/techsupport/alerts/ike.html) or upgrade to a release that addresses the Aggressive Mode identity exposure.
  • Disable IKE Aggressive Mode for shared secret authentication and use Main Mode where the environment permits.
  • Move away from shared secret authentication toward certificate-based IKE authentication.
  • Restrict IKE (UDP 500/4500) exposure to trusted source addresses and monitor for negotiation attempts from untrusted networks.

Detection

  • Monitor IKE negotiation traffic for Aggressive Mode exchanges and log source addresses initiating them.
  • Alert on repeated IKE negotiation attempts from a single source, which may indicate username enumeration.
  • Correlate IKE negotiation logs with subsequent authentication failures for the same usernames.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1623 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2002-1623), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.