EIP-2026-118354
PRE-CVECheck Point Software Firewall-1 3.0/1 4.0 - Session Agent Impersonation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118354. PoCs published by Andrew Danforth.
AI-analyzed exploit summary This Perl script exploits a vulnerability in Check Point Firewall-1 Session Agent (prior to FW-1 4.1) by impersonating the firewall module to trick users into revealing their credentials. It connects to the agent on port 261 and sends crafted messages to prompt for and capture username/password in cleartext.
Description
Check Point Software Firewall-1 3.0/1 4.0 - Session Agent Impersonation
Exploits (1)
This Perl script exploits a vulnerability in Check Point Firewall-1 Session Agent (prior to FW-1 4.1) by impersonating the firewall module to trick users into revealing their credentials. It connects to the agent on port 261 and sends crafted messages to prompt for and capture username/password in cleartext.