더 이상 사용되지 않는 IKEv1 키 교환에서 Remote Access 및 Mobile Access 인증서 검증의 논리 흐름 약점으로 인해, 인증되지 않은 원격 공격자가 사용자 인증을 우회하고 유효한 사용자 비밀번호 없이 원격 접근 VPN 연결을 설정할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
영향 제품·버전
제품 checkpoint Quantum Security Gateway, Spark Firewalls, gaia os
영향 버전 checkpoint Quantum Security Gateway, Spark Firewalls, gaia os >= R82.10 with Jumbo Hotfix Take 19 or below, >= R82 with Jumbo Hotfix Take 103 or below, >= R81.20 with Jumbo Hotfix Take 141 or below, >= R81.10, R81, and R80.40, >= R80.20.X, R81.10.X, and R82.00.X, >= r80.40 < r81.20, r81.20, r82, r82.10, >= r80.20.00 < r81.10.17, r81.10.17, >= r80.20.00 < r82.00.10, r82.00.10
수정 버전 checkpoint Quantum Security Gateway, Spark Firewalls, gaia os r81.20, r81.10.17, r82.00.10
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 기한: 2026.06.11
해당사항 확인방법
checkpoint Quantum Security Gateway, Spark Firewalls, gaia os의 현재 전체 버전이 공식 영향 범위(checkpoint Quantum Security Gateway, Spark Firewalls, gaia os >= R82.10 with Jumbo Hotfix Take 19 or below, >= R82 with Jumbo Hotfix Take 103 or below, >= R81.20 with Jumbo Hotfix Take 141 or below, >= R81.10, R81, and R80.40, >= R80.20.X, R81.10.X, and R82.00.X, >= r80.40 < r81.20, r81.20, r82, r82.10, >= r80.20.00 < r81.10.17, r81.10.17, >= r80.20.00 < r82.00.10, r82.00.10)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 checkpoint Quantum Security Gateway, Spark Firewalls, gaia os r81.20, r81.10.17, r82.00.10 기준을 충족하는지 확인합니다. 이어서 인증 우회 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.