ID

VAR-E-201105-0745


CVE

cve_id:CVE-2011-1827

Trust: 0.3

sources: BID: 47695

TITLE

Multiple Check Point SSL VPN On-Demand Applications Remote Code Execution Vulnerability

Trust: 0.3

sources: BID: 47695

DESCRIPTION

Multiple Check Point SSL VPN on-demand applications are prone to a remote code-execution vulnerability.
Successful exploits will allow the attacker to execute arbitrary code within the context of the currently logged-in user. Failed exploit attempts will likely result in a denial-of-service condition.

Trust: 0.3

sources: BID: 47695

AFFECTED PRODUCTS

vendor:checkmodel:point software secureplatform r75scope: - version: -

Trust: 0.6

vendor:checkmodel:point software secureplatform r70.40scope: - version: -

Trust: 0.6

vendor:checkmodel:point software vsx r67scope: - version: -

Trust: 0.3

vendor:checkmodel:point software vsx r65.20scope: - version: -

Trust: 0.3

vendor:checkmodel:point software secureplatform r71.30scope: - version: -

Trust: 0.3

vendor:checkmodel:point software secureplatform r65.70scope: - version: -

Trust: 0.3

vendor:checkmodel:point software ipso6 r75scope: - version: -

Trust: 0.3

vendor:checkmodel:point software ipso6 r71.30scope: - version: -

Trust: 0.3

vendor:checkmodel:point software ipso6 r70.40scope: - version: -

Trust: 0.3

vendor:checkmodel:point software ipso6 r65.70scope: - version: -

Trust: 0.3

vendor:checkmodel:point software connectra r66.1nscope: - version: -

Trust: 0.3

vendor:checkmodel:point software connectra r66.1scope: - version: -

Trust: 0.3

sources: BID: 47695

EXPLOIT

An exploit code and a video demonstrating the vulnerability is available. Please see the references for more information.

Trust: 0.3

sources: BID: 47695

PRICE

Free

Trust: 0.3

sources: BID: 47695

TYPE

Design Error

Trust: 0.3

sources: BID: 47695

CREDITS

Johannes Greil of SEC Consult Unternehmensberatung

Trust: 0.3

sources: BID: 47695

EXTERNAL IDS

db:NVDid:CVE-2011-1827

Trust: 0.3

db:BIDid:47695

Trust: 0.3

sources: BID: 47695

REFERENCES

url:https://www.sec-consult.com/files/20110810-0_checkpoint_deployment_agent_remote_file_upload_and_cmd_exec_cve-2011-1827.txt

Trust: 0.3

url:https://supportcenter.checkpoint.com/supportcenter/portal?eventsubmit_dogoviewsolutiondetails=&solutionid=sk62410

Trust: 0.3

url:http://www.microsoft.com/technet/security/advisory/2562937.mspx

Trust: 0.3

url:http://www.checkpoint.com

Trust: 0.3

sources: BID: 47695

SOURCES

db:BIDid:47695

LAST UPDATE DATE

2022-07-27T09:22:19.728000+00:00


SOURCES UPDATE DATE

db:BIDid:47695date:2011-08-18T18:50:00

SOURCES RELEASE DATE

db:BIDid:47695date:2011-05-03T00:00:00