By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Check Point Patches Two Critical VPN Certificate Vulnerabilities

Check Point has released patches for two critical vulnerabilities discovered in the handling of VPN certificates within its firewall and management products. These flaws, both rated with a severity score of 9.8 out of 10, could potentially enable an unauthenticated remote attacker to execute arbitrary code on affected systems. The company stated that exploitation of these vulnerabilities is contingent on specific, yet undisclosed, conditions. The first vulnerability impacts Check Point's Security Gateways, which serve as the company's primary firewall appliances. The second vulnerability affects both these Security Gateways and the broader Security Management products, indicating a wider potential attack surface.
These vulnerabilities were disclosed by Check Point on March 11, 2024, following their discovery by the company's own threat intelligence researchers. The Security Gateways are hardware appliances designed to protect networks by inspecting traffic and enforcing security policies, often acting as the first line of defense against external threats. The Security Management products are used to configure, manage, and monitor these gateways and other Check Point security solutions across an organization's infrastructure. The ability for an unauthenticated attacker to achieve Remote Code Execution (RCE) is considered one of the most severe types of security flaws, as it allows an attacker to take complete control of a vulnerable system without needing any prior credentials or access.
While Check Point has not detailed the specific conditions required for exploitation, the high severity rating suggests that successful attacks could have significant consequences for organizations relying on these products for network security. The company has urged its customers to update their systems to the patched versions as soon as possible to mitigate the risk. The disclosure follows a pattern of increasing sophistication in cyberattacks targeting network infrastructure, where vulnerabilities in core security components like VPNs and firewalls are prime targets.
Check Point Software Technologies Ltd. is a global cybersecurity company that provides a wide range of security solutions, including firewalls, endpoint security, cloud security, and threat intelligence. The company's products are used by businesses of all sizes to protect their networks and data from cyber threats. The patching of these critical vulnerabilities underscores the ongoing challenges in maintaining robust security in complex IT environments, especially with the proliferation of remote work which often relies heavily on secure VPN connections. The specific details of the vulnerabilities remain limited, but the high CVSS scores and the potential for RCE highlight the urgency for customers to apply the provided security updates.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.