CVE-2000-1037

Check Point Firewall-1 3.0-4.1 - Info Disclosure

Title source: llm

Description

Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Gregory Duchemin · bashremotemultiple
https://www.exploit-db.com/exploits/20216
exploitdb WORKING POC VERIFIED
by Nelson Brito · perlremotemultiple
https://www.exploit-db.com/exploits/20215

Scores

EPSS 0.1210
EPSS Percentile 93.8%

Details

Status published
Products (3)
checkpoint/firewall-1 3.0
checkpoint/firewall-1 4.0
checkpoint/firewall-1 4.1
Published Dec 11, 2000
Tracked Since Feb 18, 2026