CVE-2026-50751

Kritisch9.3Veröffentlicht am 8. Juni 2026

Eine Schwachstelle im logischen Ablauf bei der Zertifikatsvalidierung von Remote Access und Mobile Access im veralteten IKEv1-Schlüsselaustausch ermöglicht es einem nicht authentifizierten Remote-Angreifer, die Benutzerauthentifizierung zu umgehen und eine Remote-Access-VPN-Verbindung ohne gültiges Benutzerpasswort herzustellen.

Aktiv ausgenutzt

  • Seit dem 8. Juni 2026 im CISA-Katalog ausgenutzter Schwachstellen
  • US-Bundesbehörden müssen sie bis zum 11. Juni 2026 beheben (BOD 22-01)
  • Am Tag der Veröffentlichung angegriffen
  • Durch Sensoren bestätigt, nicht nur durch Meldungen
  • In Ransomware-Kampagnen eingesetzt

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Quelle: CISA KEV · 4. Sept. 2026 10. Aug. 2026 30. Juli 2026 22. Juli 2026 20. Juli 2026 18. Juli 2026

CVSS-Score9.3 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Schwachstellentyp (CWE)CWE-287
Herstellercheckpoint

Betroffene Produkte

HerstellerProduktVersionen
checkpointgaia os< r81.20
checkpointgaia embedded< r81.10.17
checkpointquantum spark 1530-
checkpointquantum spark 1550-
checkpointquantum spark 1570-
checkpointquantum spark 1570r-
checkpointquantum spark 1590-
checkpointquantum spark 1595r-
checkpointquantum spark 1600-
checkpointquantum spark 1800-
checkpointquantum spark 1900-
checkpointquantum spark 2000-
checkpointquantum spark 1535-
checkpointquantum spark 1555-
checkpointquantum spark 1575-
checkpointquantum spark 1575r-
checkpointquantum spark 2530-
checkpointquantum spark 2550-
checkpointquantum spark 2560-
checkpointquantum spark 2570-
checkpointquantum spark 2580-
checkpointquantum spark 2590-

Verwandte Artikel

This product uses the NVD API but is not endorsed or certified by the NVD.

Die technische Beschreibung ist unsere Übersetzung des englischen NVD-Originaltexts.

CVE-Datenbank