CVE-2026-48132
BaseFortify
Publication date: 2026-05-26
Last updated on: 2026-05-26
Assigner: Check Point Software Technologies Ltd.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| check_point_software_technologies | security_gateway | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-125 | The product reads data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
The primary impact of this vulnerability is a denial of service condition.
An attacker can send specially crafted IKE packets that cause the VPN processing service to crash or restart unexpectedly.
This results in temporary interruption of VPN traffic and negotiations, potentially disrupting secure communications.
Can you explain this vulnerability to me?
This vulnerability occurs because the Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T (Network Address Translation Traversal) is used on UDP port 4500.
A specially crafted or malformed packet exploiting this flaw can cause the VPN processing service to terminate unexpectedly.
This leads to a denial of service, causing temporary interruption of VPN negotiations and traffic.
How can this vulnerability be detected on my network or system? Can you suggest some commands?
This vulnerability involves the Security Gateway incorrectly validating length values in certain IKE packets when NAT-T (UDP port 4500) is used, causing the VPN processing service to terminate unexpectedly.
To detect this vulnerability on your network or system, monitoring for unexpected restarts or interruptions of the VPN processing service related to IKE traffic over UDP port 4500 is recommended.
Specific commands or detection methods are not provided in the available resources.
What immediate steps should I take to mitigate this vulnerability?
The available information does not specify immediate mitigation steps or recommended actions to address this vulnerability.