Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-2679

Overview

Vulnerability Score 7.8 7.8
CVE Id CVE-2004-2679
Last Modified 05 Sep 2008 04:44:49
Published 31 Dec 2004 12:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2004-2679

Summary

Check Point Firewall-1 4.1 up to NG AI R55 allows remote attackers to obtain potentially sensitive information by sending an Internet Key Exchange (IKE) with a certain Vendor ID payload that causes Firewall-1 to return a response containing version and other information.

Vulnerable Systems

Application

  • Checkpoint Firewall-1 4.0

  • Checkpoint Firewall-1 4.1

  • Checkpoint Firewall-1 R55


References

XF - fw1-vendorid-info-disclosure(16434)

BID - 10558

MISC - http://www.nta-monitor.com/news/checkpoint2004/index.htm

FULLDISC - 20040616 Checkpoint Firewall-1 IKE Vendor ID information leakage


Last Updated: 27 May 2016 10:39:34