CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Versions Of Firewall-1/VPN-1
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-18
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Advisory on possible DoS - R55 and up

TITLE:
CheckPoint VPN-1 IP Address Collision Security Issue

SECUNIA ADVISORY ID:
SA29394

VERIFY ADVISORY:
CheckPoint VPN-1 IP Address Collision Security Issue - Advisories - Secunia

CRITICAL:
Less critical

IMPACT:
Exposure of sensitive information, DoS

WHERE:
From local network

SOFTWARE:
Check Point VPN-1/FireWall-1 NG with Application Intelligence (AI)
Check Point VPN-1/FireWall-1 NG with Application Intelligence (AI) - Vulnerability Report - Secunia
Check Point VPN-1 UTM NGX
Check Point VPN-1 UTM NGX - Vulnerability Report - Secunia
Check Point VPN-1 Power NGX
Check Point VPN-1 Power NGX - Vulnerability Report - Secunia

DESCRIPTION:
Robert Mitchell has reported a security issue in CheckPoint VPN-1,
which can lead to a DoS (Denial of Service) or disclosure of
sensitive information.

The security issue is caused due to an error in the handling IP
address collisions and can lead to a DoS or disclosure of sensitive
information.

The problem occurs when a remote access client has an IP address,
which is also defined in the encryption domain of a gateway that has
a site-to-site VPN tunnel to the gateway the client connects to.

SOLUTION:
The vendor has issued hotfixes to resolve the issue (see vendor
advisory for details).

PROVIDED AND/OR DISCOVERED BY:
Robert Mitchell

ORIGINAL ADVISORY:
CheckPoint:
https://secureknowledge.checkpoint.c...ion&id=sk34579
Check Point Software Technologies: Download Center

Robert Mitchell:
Pure Security
Reply With Quote
  #2 (permalink)  
Old 2008-03-18
Senior Member
 
Join Date: 2007-07-16
Posts: 618
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Advisory on possible DoS - R55 and up

I'm going to "out" myself on this - this is a vulnerability I discovered.

Check Point and Secunia's advisory, IMHO, understate the risk of this. If you are running Check Point with the following conditions :

1. NGX (Any version);
2. SecuRemote users not using Office Mode; and
3. Both Client-Site and Site-Site VPNs terminating on the same gateway;

then you really need to look at this advisory and understand its implications. At the very least, unless you are running Office Mode and can force all your Remote Access users to use it, do *not* turn on SecuRemote back-connections. That mitigates the worst parts of the threat.

Also, be aware that the hotfix provides logs on the SmartView Tracker, but does not provide any feedback to the SecuRemote User on why their VPN connection fails. The user will authenticate successfully and send traffic, but it will be dropped at the Gateway. When the support call comes in from the user, you'll see "VPN Error Code 1" in the information field. The only way to fix the user's problem at this stage is to change their machine's IP address and/or use Office Mode.
Reply With Quote
  #3 (permalink)  
Old 2008-03-19
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Advisory on possible DoS - R55 and up

Quote:
Originally Posted by Thorpuse View Post
Also, be aware that the hotfix provides logs on the SmartView Tracker, but does not provide any feedback to the SecuRemote User on why their VPN connection fails. The user will authenticate successfully and send traffic, but it will be dropped at the Gateway. When the support call comes in from the user, you'll see "VPN Error Code 1" in the information field. The only way to fix the user's problem at this stage is to change their machine's IP address and/or use Office Mode.
A malicious user would be able to set up their internal IPs to mimic Gateway B hosts they want to steal data from. Enforcing the use of OM would the be only solution. Unfortunately OM isn't 100% reliable..there's always that one client that won't use it's assigned OM address.

Good work on the discovery.
__________________
Its all in the documentation.
Reply With Quote
  #4 (permalink)  
Old 2008-03-31
Senior Member
 
Join Date: 2006-02-18
Posts: 103
Rep Power: 3
ChrisA has an average reputation (10+)
Default Re: Advisory on possible DoS - R55 and up

I have a stupid question about this advisory. I'm running R62 on my Nokias. When I look up sk34579, in the section listing hotfixes for each version of CheckPoint, the hotfix for R62 has "GA" on the end; ie "For VPN-1 Power/UTM NGX R62 GA." Why is "GA" on here? I know it means "Generally Available" but is this a special version of R62 that was released at some point? The other versions don't have this "GA" designation in this sk item. Does this hotfix work for all R62 versions? If not, does this mean there's no hotfix for my version of R62? Please advise.

Thanks,
Chris.
Reply With Quote
  #5 (permalink)  
Old 2008-03-31
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Advisory on possible DoS - R55 and up

That is the right HF, just someone new named it.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 23:50.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0