Lucene search

K
cve[email protected]CVE-2013-5636
HistoryNov 30, 2013 - 11:43 a.m.

CVE-2013-5636

2013-11-3011:43:54
CWE-255
web.nvd.nist.gov
58
check point
endpoint security
cve-2013-5636
media encryption
epm explorer
device-locking
security vulnerability

3.3 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

35.5%

Unlock.exe in Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not associate password failures with a device ID, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by overwriting DVREM.EPM with a copy of itself after each few password guesses.

Affected configurations

NVD
Node
checkpointendpoint_securityMatche80-vpn_blade
OR
checkpointendpoint_securityMatche80.10-vpn_blade
OR
checkpointendpoint_securityMatche80.20-vpn_blade
OR
checkpointendpoint_securityMatche80.30-vpn_blade
OR
checkpointendpoint_securityMatche80.40-vpn_blade
OR
checkpointendpoint_securityMatche80.41-vpn_blade
OR
checkpointendpoint_securityMatche80.50-vpn_blade

3.3 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

35.5%