Skip to main content

Check Point SSL VPN On-Demand Applications Remote Code Execution Vulnerability

Last Update Date: 4 May 2011 12:18 Release Date: 4 May 2011 5814 Views

RISK: High Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in Check Point products, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the SSL Network Extender (SNX), SecureWorkSpace and Endpoint Security On-Demand application when deployed through a browser, which could allow attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.


Impact

  • Remote Code Execution

System / Technologies affected

  • Check Point SecurePlatform
  • Check Point IPSO6
  • Check Point Connectra
  • Check Point VSX

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link