Who is affected
Check Point Security Gateway and Check Point Spark Firewall are vulnerable when configured to use Site to Site VPN or Remote Access VPN. An unauthenticated remote attacker can exploit improper certificate validation to execute arbitrary code. The record does not specify affected versions, patch availability, or whether on-premises and cloud deployments are equally exposed.
How to check whether this touches you
- Inventory all Check Point Security Gateway and Spark Firewall instances in your environment and note their deployment type (on-premises, cloud, hybrid).
- For each instance, confirm whether Site to Site VPN or Remote Access VPN is enabled in the configuration.
- Establish whether each affected instance is reachable from the internet or from untrusted networks; check firewall rules, network segmentation, and any reverse proxies or load balancers in front of it.
- Query the running version via the management console or SSH access to the appliance; compare against Check Point's advisory for affected and patched versions.
- Check logs for any unusual certificate validation errors, failed authentication attempts, or unexpected connections to the VPN endpoints.
What to do
- Review Check Point's published advisory for this CVE to identify which versions are affected and what patches or mitigations are available.
- If you cannot patch immediately, disable Site to Site VPN and Remote Access VPN on affected instances if business operations permit; otherwise, restrict VPN endpoint access to known, trusted IP ranges via firewall rules.
- Enable detailed logging of all VPN authentication attempts and certificate validation events; ship logs to a centralised, immutable store.
- Schedule patching in accordance with CISA BOD 26-04 guidance (which prioritises internet-facing critical infrastructure); treat this as a high-priority change because unauthenticated remote code execution requires no prior access.
- If patches are unavailable and you cannot disable or isolate the service, escalate to Check Point support and your information security leadership to evaluate whether continued use is acceptable under your risk policy.
If you find you were exposed
Exploitation of improper certificate validation typically occurs before public disclosure; the record does not specify when active use began. Search your VPN authentication logs, firewall access logs, and system event logs for anomalous connections, failed certificate checks, or command execution around the time the vulnerability became known in your supply chain. Log retention is usually the limiting factor—work backwards from today and retrieve as much history as your systems retain.