vendor:
SecureRemote
by:
Haroon Meer & Roelof Temmingh
4,3
CVSS
MEDIUM
Information Gathering
200
CWE
Product Name: SecureRemote
Affected Version From: Older versions
Affected Version To: Latest version
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2001
SecureRemote Information Gathering Vulnerability
SecureRemote is the proprietary VPN infrastructure designed by Check Point Software, and included with some versions of Firewall-1. A problem with the package allows remote users to gain information about internal networks. Older versions of the package send network topology information to SecureRemote connections prior to authentication, allowing an information gathering attack.
Mitigation:
Upgrade to the latest version of SecureRemote.