← Vulnerability feed

Vulnerability record · CVE-2008-1397 · published 20 March 2008

CVE-2008-1397: Checkpoint check point vpn-1 pro permissions and access controls vulnerability

Checkpoint · Check Point Vpn 1 Pro

Check Point VPN-1 Power/UTM, with NGX R60 through R65 and NG AI R55 software, allows remote authenticated users to cause a denial of service (site-to-site VPN tunnel outage), and possibly intercept network traffic, by configuring the local RFC1918 IP address to be the same as one of this tunnel's endpoint RFC1918 IP addresses, and then using SecuRemote to connect to a network interface at the other endpoint.

6.5 CVSS 2.0 Medium EPSS 2.2% · top 18.5% CWE-264 · Permissions and access controls
6.5CVSS 2.0 base score
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
18References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Check Point VPN-1 Power/UTM, with NGX R60 through R65 and NG AI R55 software, allows remote authenticated users to cause a denial of service (site-to-site VPN tunnel outage), and possibly intercept network traffic, by configuring the local RFC1918 IP address to be the same as one of this tunnel's endpoint RFC1918 IP addresses, and then using SecuRemote to connect to a network interface at the other endpoint.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1397 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0469Checkpoint firewall-1 vulnerabilityBuffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG …EPSS 5.0%10.0CVE-2004-0040Checkpoint firewall-1 vulnerabilityStack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows…EPSS 7.6%9.3CVE-2011-1827Checkpoint connectra ngx vulnerabilityMultiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distributed by S…EPSS 4.5%7.8CVE-2005-3673Checkpoint check point vulnerabilityThe Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain c…EPSS 4.9%7.5CVE-2004-0079Cisco firewall services module null pointer dereference vulnerabilityThe do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) vi…EPSS 9.5%7.5CVE-2004-0699Checkpoint firewall-1 vulnerabilityHeap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers …EPSS 5.9%7.5CVE-2001-1176Checkpoint firewall-1 vulnerabilityFormat string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via fo…EPSS 2.8%7.2CVE-2006-0255Checkpoint vpn-1 vulnerabilityUnquoted Windows search path vulnerability in Check Point VPN-1 SecureClient might allow local users to gain privileges via a malicious "program.exe"…EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2008-1397), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.