Impact
A heap-based buffer overflow occurs during the parsing of ASN.1-encoded VPN certificates in Check Point Quantum Security Management and Quantum Security Gateway devices, allowing an unauthenticated remote attacker to execute arbitrary code. This flaw can lead to complete compromise of the device, including persistence and lateral movement capabilities, by overrunning memory boundaries in the certificate decoding routine.
Affected Systems
The affected products are Check Point Quantum Security Management and Check Point Quantum Security Gateway. No specific version numbers are listed in the advisory, so all releases prior to the latest security update from Check Point should be considered vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity risk, and the EPSS score of 4% suggests a non-negligible likelihood of exploitation. This vulnerability is not listed in the CISA KEV catalog. It is inferred that the attack vector involves remote delivery of a malicious VPN certificate, as the advisory mentions an unauthenticated remote attacker; however, the exact transport mechanism (for example, VPN connection or web interface) is not explicitly stated. Because no authentication is required to trigger the vulnerability, the risk surface is broad for any host that can reach the affected systems.
OpenCVE Enrichment