Check Point Patches Two Critical VPN Certificate Flaws
Check Point has patched two critical, 9.8-rated vulnerabilities in how its firewall and management products handle VPN certificates. Both flaws could enable unauthenticated remote code execution under specific, undisclosed conditions, making accurate gateway inventory and patch prioritization essential.

Check Point has disclosed and patched two critical vulnerabilities involving VPN certificate handling in its firewall and management products. Both are rated 9.8 and could allow an unauthenticated remote attacker to execute code under specific conditions that the company has not described. The limited detail makes asset-level exposure assessment especially important.
What Check Point Disclosed
One vulnerability affects Check Point Security Gateways, the appliances responsible for enforcing firewall policy. The affected product set across the two flaws also includes Check Point management products.
Both vulnerabilities concern the processing of VPN certificates. Check Point says exploitation could result in unauthenticated remote code execution, although the precise conditions required for a successful attack remain undisclosed.
Why Accurate Inventory Matters
A critical rating establishes urgency, but it does not tell an infrastructure team which devices require action. Operators need to locate every affected gateway and related management system, establish their installed releases and roles, and determine which systems handle relevant VPN connections and certificates.
The absence of detailed exploitation conditions should not be treated as evidence that a deployment is unaffected. Exposure decisions should be based on confirmed product and configuration data rather than assumptions about how the flaws work.
Practical Response Priorities
- Build a complete inventory of Check Point Security Gateways and associated management systems.
- Identify devices that terminate VPN connections or process VPN certificates.
- Compare installed software releases with Check Point's fixed-release guidance.
- Back up configurations before maintenance and preserve a clear change history.
- Apply the available patches according to operational risk and exposure.
- Validate VPN operation, firewall policy and configuration compliance after remediation.
- Review support status for older appliances that may complicate patching.
How ConnectMyAssets Helps
ConnectMyAssets provides an on-prem workflow for managing the infrastructure data needed during this type of vulnerability response:
- Dynamic CMDB automatically discovers supported Check Point assets and records the gateway and management inventory.
- CVE Tracking associates published vulnerabilities with individual assets as identifiers and affected-release information are confirmed.
- Network Topology helps teams understand where affected gateways sit and which network paths depend on them.
- Backup & History preserves configuration versions with SHA256 verification and supports one-click rollback if an approved change causes problems.
- Compliance Engine evaluates configurations against policies and frameworks including NIS2, ISO 27001, PCI-DSS, CISA and NIST.
- Automation & ZTP supports consistent, approved follow-up configuration changes across multiple devices.
- End-of-Life and End-of-Support tracking highlights assets whose support status could obstruct remediation.
Because ConnectMyAssets runs as a hardened on-prem OVA, firewall inventory, configurations, credentials and vulnerability data remain within the organization's environment.
Source: The Hacker News



