VulnerabilityModified
CVE-2001-1158
Check Point VPN-1/FireWall-1 4.1 base.def contains a default macro, accept_fw1_rdp, which can allow remote attackers to bypass intended restrictions with forged RDP (internal protocol) headers to UDP port 259 of arbitrary hosts.
HIGH 7.5EPSS 3.20%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Check Point VPN-1/FireWall-1 4.1 base.def contains a default macro, accept_fw1_rdp, which can allow remote attackers to bypass intended restrictions with forged RDP (internal protocol) headers to UDP port 259 of arbitrary hosts.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.20% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- checkpoint/firewall-1
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-07/0128.htmlPatch, Vendor Advisory
- http://ciac.llnl.gov/ciac/bulletins/l-109.shtml
- http://online.securityfocus.com/cgi-bin/archive.pl?id=1&start=2002-03-11&end=2002-03-17&mid=195647&threads=1
- http://www.cert.org/advisories/CA-2001-17.htmlUS Government Resource
- http://www.checkpoint.com/techsupport/alerts/rdp.html
- http://www.kb.cert.org/vuls/id/310295US Government Resource
- http://www.osvdb.org/1884
- http://www.securityfocus.com/bid/2952Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6815
- http://archives.neohapsis.com/archives/bugtraq/2001-07/0128.htmlPatch, Vendor Advisory
- http://ciac.llnl.gov/ciac/bulletins/l-109.shtml
- http://online.securityfocus.com/cgi-bin/archive.pl?id=1&start=2002-03-11&end=2002-03-17&mid=195647&threads=1
- http://www.cert.org/advisories/CA-2001-17.htmlUS Government Resource
- http://www.checkpoint.com/techsupport/alerts/rdp.html
- http://www.kb.cert.org/vuls/id/310295US Government Resource
- http://www.osvdb.org/1884
- http://www.securityfocus.com/bid/2952Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6815
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.