SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-8456

Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server.

MEDIUM 5.9EPSS 20.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 20.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
20.39% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
checkpoint/ipsec vpn
Source
cve@checkpoint.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.