QSearchQSearch

CVE-2026-50751

9.3 CRITICAL

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticate...

Published: 2026-06-08 · Last updated: 2026-06-09

Severity and scoring

CVSS
9.3 CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CWE
CWE-287

Affected products

VendorProduct
checkpointgaia_embedded, gaia_os

Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2022-23742 Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low ... (7.8 HIGH)

Same CWE

  • CVE-2026-47166 ImageMagick is free and open-source software used for editing and manipulating digital images (5.7 MEDIUM)
  • CVE-2026-46705 Russh is a Rust SSH client & server library (5.3 MEDIUM)
  • CVE-2022-48575 A person with access to a Mac may be able to bypass Login Window (3.5 LOW)
  • CVE-2026-45567 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers (8.3 HIGH)
  • CVE-2026-47838 SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wr... (6.8 MEDIUM)