Executive Summary

The Dutch NCSC has issued a warning about two critical vulnerabilities in Check Point VPN products, both rated with a CVSS score of 9.8. These flaws could enable remote code execution and are actively exploited, posing a significant risk to networks. Immediate action is required to mitigate these vulnerabilities.

Technical Analysis

The vulnerabilities are present in Check Point VPN products and have been assigned a CVSS score of 9.8. This score indicates a critical severity level, suggesting that the flaws could be easily exploited and have a high impact on the affected systems.

How It Gets Exploited

An unauthenticated remote attacker could exploit these vulnerabilities by sending a crafted request to the Check Point VPN endpoint. When the flawed component processes this request, it fails to properly validate the input, leading to a buffer overflow that could result in remote code execution. This would allow the attacker to execute arbitrary code on the affected system, potentially gaining access to sensitive data and other resources on the network.

Impact Assessment

The impact of these vulnerabilities is significant, as they could allow an attacker to gain remote code execution on the affected Check Point VPN products. This could lead to a range of malicious activities, including data exfiltration, lateral movement within the network, and disruption of critical services. The CVSS score of 9.8 indicates a high severity level, emphasizing the need for immediate action.

Recommended Actions

To mitigate these vulnerabilities, the following actions are recommended:

  • Update Check Point VPN products to the latest version, which includes patches for these vulnerabilities.
  • Restrict access to VPN services to only those who require it, reducing the attack surface.
  • Implement network segmentation to limit lateral movement in case of a breach.
  • Monitor VPN access and authentication logs for suspicious activity.

Sources

Security Affairs