Checkpoint Firewall-1 Valid Username...

- AV AC AU C I A
发布: 2000-11-01
修订: 2025-04-13

Checkpoint Firewall-1 is a popular firewall package available from Checkpoint Software Technologies. A vulnerability exists in Firewall-1 whereby an attacker can determine a valid username by the response given by the firewall to authentication requests (port 259 on the firewall) from a remote client. Upon connecting to the firewall, the attacker enters a username and password. If the username and password are invalid, the firewall will respond with "<username> not found". If the username is valid, and the password is invalid, the firewall will respond with "Access denied by Firewall-1 authentication". Upon successfully determining a valid username, a remote attacker could then attempt a brute force or password grinding attack to determine the password for the valid username. If successful, an attacker could then gain access to the firewall based on that user's privileges.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息