Lucene search

K
cveMitreCVE-2007-0471
HistoryJan 24, 2007 - 1:28 a.m.

CVE-2007-0471

2007-01-2401:28:00
CWE-264
mitre
web.nvd.nist.gov
73
cve-2007-0471
check point
connectra ngx r62
ics
security bypass
vulnerability
remote attack
authentication token
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

High

EPSS

0.553

Percentile

97.7%

sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authentication token.

Affected configurations

Nvd
Node
checkpointconnectra_ngxRanger62
VendorProductVersionCPE
checkpointconnectra_ngx*cpe:2.3:a:checkpoint:connectra_ngx:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

High

EPSS

0.553

Percentile

97.7%