Title: Check Point VPN-1 ASN.1 Buffer Overflow Vulnerability
Severity: CRITICAL
Description:
VPN-1 is the firewall and virtual private network software package distributed by Check Point Software Technologies.
A remote buffer overflow vulnerability is reported in Check Point VPN-1 that may allow a remote attacker to execute arbitrary code in order to gain unauthorized access. This issue results from insufficient boundary checks performed by the application when processing user-supplied data.
ASN.1 (Abstract Syntax Notation One) is used to encode various parts of ISAKMP (Internet Security Association and Key Management Protocol) network traffic. VPN-1 is reported to contain a flaw in its parsing of ASN.1 data that allows for a heap buffer overflow. This overflow occurs during the initial key exchange process.
This vulnerability can be triggered with a single UDP packet. Since ISAKMP uses the UDP transport, a spoofed source address can be used in an attack.
Check Point reports that for a single packet attack to succeed, VPN-1 must be configured for aggressive mode key exchange. Without aggressive mode, an attacker must initiate a real key negotiation session.
This vulnerability can lead to remote code execution in the context of the VPN-1 process. This can lead to a complete system compromise.
Check Point has released an advisory and fixes for this issue.
Affected Products:
- Check Point Software FireWall-1 GX 2.0.0
- Check Point Software FireWall-1 GX 2.5.0
- Check Point Software FireWall-1 Next Generation FP3
- Check Point Software FireWall-1 VSX 2.0.1
- Check Point Software FireWall-1 VSX NG with Application Intelligence
- Check Point Software NG-AI R54
- Check Point Software NG-AI R55
- Check Point Software NG-AI R55W
- Check Point Software Provider-1 NG with Application Intelligence R54
- Check Point Software Provider-1 NG with Application Intelligence R55
- Check Point Software SSL Network Extender
- Check Point Software SecuRemote 4.0.0
- Check Point Software SecuRemote 4.1.0
- Check Point Software SecuRemote NG with Application Intelligence R56
- Check Point Software SecureClient 4.0.0
- Check Point Software SecureClient 4.1.0
- Check Point Software SecureClient NG with Application Intelligence R56
- Check Point Software VPN-1 VSX 2.0.1
- Check Point Software VPN-1/Firewall-1 VSX 2.0.1
- Check Point Software VPN-1/Firewall-1 VSX NG with AI Release 1
- Check Point Software VPN-1/Firewall-1 VSX NG with AI Release 2
- Check Point Software VSX FireWall-1 GX
References:
- Check Point Software: ASN.1 Alert
- Check Point Software: Check Point Technical Support
- Internet Security Systems: Check Point VPN-1 ASN.1 Decoding Remote Compromise
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.