Impact
Improper certificate trust validation during VPN negotiation allows an unauthenticated remote attacker to execute arbitrary code on a Check Point Quantum Security Gateway. The flaw bypasses the normal certificate verification process, enabling the attacker to inject and run malicious payloads on the gateway device without needing any prior credential or local access.
Affected Systems
The vulnerability affects Check Point Quantum Security Gateway devices. No specific firmware or software versions are listed in the advisory, so all currently deployed instances should be considered potentially vulnerable until vendor confirmation is received.
Risk and Exploitability
With a CVSS score of 9.8 the severity is critical. Although EPSS data is not available and the flaw is not yet listed in CISA’s KEV catalog, the unauthenticated remote nature of the attack vector suggests that it could be exploited by adversaries targeting the VPN component of the gateway. The absence of a KEV listing does not diminish the risk, as the flaw allows direct code execution on the gateway, potentially compromising network security and enabling further lateral movement.
OpenCVE Enrichment