Description
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
Published: 2026-09-09
Score: 9.8 Critical
EPSS: 3.7% Low
KEV: No
Impact: Remote code execution through heap overflow
Action: Immediate Patch
AI Analysis

Impact

A heap-based buffer overflow occurs during the parsing of ASN.1-encoded VPN certificates in Check Point Quantum Security Management and Quantum Security Gateway devices, allowing an unauthenticated remote attacker to execute arbitrary code. This flaw can lead to complete compromise of the device, including persistence and lateral movement capabilities, by overrunning memory boundaries in the certificate decoding routine.

Affected Systems

The affected products are Check Point Quantum Security Management and Check Point Quantum Security Gateway. No specific version numbers are listed in the advisory, so all releases prior to the latest security update from Check Point should be considered vulnerable.

Risk and Exploitability

The CVSS score of 9.8 indicates a high severity risk, and the EPSS score of 4% suggests a non-negligible likelihood of exploitation. This vulnerability is not listed in the CISA KEV catalog. It is inferred that the attack vector involves remote delivery of a malicious VPN certificate, as the advisory mentions an unauthenticated remote attacker; however, the exact transport mechanism (for example, VPN connection or web interface) is not explicitly stated. Because no authentication is required to trigger the vulnerability, the risk surface is broad for any host that can reach the affected systems.

Generated by OpenCVE AI on September 25, 2026 at 01:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available firmware or software update from Check Point that addresses the heap overflow in VPN certificate decoding.
  • Restrict VPN access to trusted IP addresses using whitelisting and enforce multi‑factor authentication for VPN connections to reduce exposure.
  • Implement logging and monitoring for certificate parsing errors and anomalous VPN traffic; configure alerts for unusual certificate contents or decoding failures that may indicate an attempted exploitation.
  • Consider isolating vulnerable appliances from critical network segments until patches are applied.

Generated by OpenCVE AI on September 25, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Checkpoint
Checkpoint quantum Security Gateway
Checkpoint quantum Security Management
Vendors & Products Checkpoint
Checkpoint quantum Security Gateway
Checkpoint quantum Security Management

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
Title Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Checkpoint Quantum Security Gateway Quantum Security Management
cve-icon MITRE

Status: PUBLISHED

Assigner: checkpoint

Published:

Updated: 2026-09-10T03:56:41.934Z

Reserved: 2026-09-03T06:38:15.701Z

Link: CVE-2026-85103

cve-icon Vulnrichment

Updated: 2026-09-09T15:14:26.489Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T13:20:43.997

Modified: 2026-09-10T04:18:18.390

Link: CVE-2026-85103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T01:30:20Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow