CVE-2005-4093 EXPLOIT
6.5
MEDIUM · CVSS 2.0 · EPSS 3.1% (pctl 88)
Patch early
A public exploit exists.
Description
Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modifying the local copy of the local.scv policy file after it has been downloaded from the VPN Endpoint.
Scoring
| CVSS | 6.5 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
| EPSS | 3.15% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-12-08 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| checkpoint | secureclient ng |
| checkpoint | vpn-1 secureclient |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Check Point VPN-1 SecureClient 4.0 < 4.1 - Policy Bypass | 2005-12-07 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/039634.html
- http://secunia.com/advisories/17837
- http://secunia.com/advisories/23395
- http://securitytracker.com/id?1015326
- http://www.mail-archive.com/swinog%40lists.swinog.ch/msg00798.html
- http://www.mail-archive.com/swinog%40lists.swinog.ch/msg00799.html
- http://www.securityfocus.com/bid/15757
- http://www.us.debian.org/security/2006/dsa-1237
- http://www.vupen.com/english/advisories/2005/2808
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-December/039634.html
- http://secunia.com/advisories/17837
- http://secunia.com/advisories/23395
- http://securitytracker.com/id?1015326
- http://www.mail-archive.com/swinog%40lists.swinog.ch/msg00798.html
- http://www.mail-archive.com/swinog%40lists.swinog.ch/msg00799.html
- http://www.securityfocus.com/bid/15757
- http://www.us.debian.org/security/2006/dsa-1237
- http://www.vupen.com/english/advisories/2005/2808
→ the Explorer · watch your stack · NVD