VDB
CVE-2001-1158
CVE-2001-1158
PUBLISHED
CVSS 7.5 HIGH
Check Point VPN-1/FireWall-1 4.1 base.def contains a default macro, accept_fw1_rdp, which can allow remote attackers to bypass intended restrictions with forged RDP (internal protocol) headers to UDP port 259 of arbitrary hosts.
EPSS 2.83% · 86.5th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
2.83%
86.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| checkpoint | firewall-1 | 4.1, 4.1, 4.1_build_41439 |
Timeline
- Jun 28, 2001 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 2952 vdb
- 20010709 Check Point FireWall-1 RDP Bypass Vulnerability mailing-list
- 20010712 RDP Bypass workaround for VPN-1/FireWall 4.1 SPx vendor-advisory
- VU#310295 third-party-advisory
- CA-2001-17 third-party-advisory
- L-109 third-party-advisory
- 20010709 Check Point response to RDP Bypass mailing-list
- 1884 vdb
- fw1-rdp-bypass(6815) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2001-1158 advisory