Vulnerability Name:

CVE-2004-0040 (CCN-14150)

Assigned:2004-02-04
Published:2004-02-04
Updated:2017-10-10
Summary:Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2004-0040

Source: BUGTRAQ
Type: UNKNOWN
20040205 Two checkpoint fw-1/vpn-1 vulns

Source: CCN
Type: CIAC Information Bulletin O-073
Check Point VPN-1 Server and VPN Client Buffer Overflow Vulnerability

Source: CIAC
Type: UNKNOWN
O-073

Source: CCN
Type: Internet Security Systems Download Center
ISS Download Center

Source: CCN
Type: US-CERT VU#873334
Check Point ISAKMP vulnerable to buffer overflow via Certificate Request

Source: CERT-VN
Type: Patch, Third Party Advisory, US Government Resource
VU#873334

Source: OSVDB
Type: UNKNOWN
3821

Source: OSVDB
Type: UNKNOWN
4432

Source: CCN
Type: OSVDB ID: 4432
Check Point VPN-1/SecuRemote ISAKMP Overflow

Source: BID
Type: Patch, Vendor Advisory
9582

Source: CCN
Type: BID-9582
Check Point VPN-1/SecuRemote ISAKMP Large Certificate Request Payload Buffer Overflow Vulnerability

Source: CCN
Type: Internet Security Systems Security Advisory, February 4, 2004
Checkpoint VPN-1/SecureClient ISAKMP Buffer Overflow

Source: ISS
Type: UNKNOWN
20040204 Checkpoint VPN-1/SecureClient ISAKMP Buffer Overflow

Source: XF
Type: UNKNOWN
vpn1-ike-bo(14150)

Source: XF
Type: UNKNOWN
vpn1-ike-bo(14150)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:checkpoint:firewall-1:4.1:*:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:4.1:sp1:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:4.1:sp2:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:4.1:sp3:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:4.1:sp4:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:4.1:sp5:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:4.1:sp5a:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:next_generation_fp0:*:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:next_generation_fp1:*:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:vpn-1:4.1:sp5a:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:vpn-1:next_generation_fp0:*:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:vpn-1:next_generation_fp1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:checkpoint:firewall-1:4.1:*:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:4.1:sp1:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:4.1:sp2:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:4.1:sp5:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:4.1:sp3:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:4.1:sp4:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:4.1:sp5a:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:vpn-1:4.1:sp5a:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:next_generation_fp1:*:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:firewall-1:next_generation_fp0:*:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:vpn-1:next_generation_fp0:*:*:*:*:*:*:*
  • OR cpe:/a:checkpoint:vpn-1:next_generation_fp1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    checkpoint firewall-1 4.1
    checkpoint firewall-1 4.1 sp1
    checkpoint firewall-1 4.1 sp2
    checkpoint firewall-1 4.1 sp3
    checkpoint firewall-1 4.1 sp4
    checkpoint firewall-1 4.1 sp5
    checkpoint firewall-1 4.1 sp5a
    checkpoint firewall-1 next_generation_fp0
    checkpoint firewall-1 next_generation_fp1
    checkpoint vpn-1 4.1 sp5a
    checkpoint vpn-1 next_generation_fp0
    checkpoint vpn-1 next_generation_fp1
    checkpoint firewall-1 4.1
    checkpoint firewall-1 4.1 sp1
    checkpoint firewall-1 4.1 sp2
    checkpoint firewall-1 4.1 sp5
    checkpoint firewall-1 4.1 sp3
    checkpoint firewall-1 4.1 sp4
    checkpoint firewall-1 4.1 sp5a
    checkpoint vpn-1 4.1 sp5a
    checkpoint firewall-1 next_generation_fp1
    checkpoint firewall-1 next_generation_fp0
    checkpoint vpn-1 next_generation_fp0
    checkpoint vpn-1 next_generation_fp1