vendor:
Firewall-1
by:
Andrew Danforth
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Firewall-1
Affected Version From: All versions prior to FW-1 4.1
Affected Version To: FW-1 4.1
Patch Exists: YES
Related CWE: CVE-2001-0240
CPE: a:check_point:firewall-1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 9x, NT
2001
Firewall-1 Session Agent Vulnerability
A vulnerability exists in the 'Session Agent' portion of Firewall-1, from Check Point. This vulnerability appears to affect all versions of the session agent prior to the one shipped in FW-1 4.1. The session agent listens on a Windows 9x or NT box for connections from the firewall, requesting user authentication for connections. This information is all transmitted in cleartext, and is unauthenticated. This means it can be sniffed. In addition, the agent accepts connections from any host. Any person who can connect to the session agent can impersonate the Firewall-1 module, and request username and password information. If supplied, this can result in the compromise of that username and password.
Mitigation:
Ensure that the Session Agent is running the latest version of Firewall-1, and that only trusted IP addresses are allowed to connect to the Session Agent.