חברת צ'ק פוינט חשפה שתי פרצות קריטיות ב-VPN המאפשרות RCE
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

◆ סיכום AI
חברת צ'ק פוינט תיקנה שתי פרצות אבטחה קריטיות (בדירוג 9.8) באופן שבו מוצרי ה-Firewall והניהול שלה מטפלים בתעודות VPN. פרצות אלו יכלו לאפשר לתוקף מרוחק לא מאומת (unauthenticated) להריץ קוד זדוני (RCE). אחת הפרצות משפיעה על ה-Security Gateways של צ'ק פוינט, והשנייה על השערים ועל ה-Security Management.
# מהמקור
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security