sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authentication token.
References
Configurations
Information
Published : 2007-01-23 17:28
Updated : 2018-10-16 09:32
NVD link : CVE-2007-0471
Mitre link : CVE-2007-0471
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
checkpoint
- connectra_ngx