Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-89xv-5cj4-39m4

Опубликовано: 08 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.

EPSS

Процентиль: 91%
0.04859
Низкий

7.4 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7.4
nvd
около 2 месяцев назад

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.

CVSS3: 7.4
fstec
2 месяца назад

Уязвимость реализации протокола Internet Key Exchange (IKEv1) межсетевых экранов Check Point Security Gateways и Check Point Spark Firewall, позволяющая нарушителю проводить атаки типа "человек посередине" и обойти проверку сертификатов в VPN-соединении

EPSS

Процентиль: 91%
0.04859
Низкий

7.4 High

CVSS3

Дефекты

CWE-295