A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
A logic error (CWE-287) in the certificate validation process during IKEv1 negotiation causes the user identity verification mechanism to be bypassed. An attacker, without possessing the correct password, is able to conduct an IKEv1 session in such a way that the system incorrectly recognizes authentication as successfully completed. As a result, a remote attacker can establish a full-fledged VPN connection within the Remote Access or Mobile Access functions.
An attacker can gain unauthorized access to an organization's internal network through a VPN tunnel, creating a risk of confidential data disclosure (High Confidentiality) and limited modifications to protected resources (Low Integrity). The vulnerability enables lateral movement within the network.
The hotfix provided by Check Point should be applied immediately in accordance with the recommendations in article sk185033 (https://support.checkpoint.com/results/sk/sk185033). Additionally, it is recommended to disable support for the deprecated IKEv1 protocol wherever it is not absolutely required, and to migrate to IKEv2.
Check Point products supporting Remote Access VPN and Mobile Access functions with deprecated IKEv1 protocol support enabled — specific versions indicated in vendor references (sk185033).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:NCheckpoint Gaia Embedded
OSCheckpointr81.10.17r82.00.10r80.20.00 – r82.00.10 (excl.)r80.20.00 – r81.10.17 (excl.)Checkpoint Gaia Os
OSCheckpointr81.20r82r82.10r80.40 – r81.20 (excl.)Checkpoint Quantum Spark 1530
HWCheckpointall versionsCheckpoint Quantum Spark 1535
HWCheckpointall versionsCheckpoint Quantum Spark 1550
HWCheckpointall versionsCheckpoint Quantum Spark 1555
HWCheckpointall versionsCheckpoint Quantum Spark 1570
HWCheckpointall versionsCheckpoint Quantum Spark 1570r
HWCheckpointall versionsCheckpoint Quantum Spark 1575
HWCheckpointall versionsCheckpoint Quantum Spark 1575r
HWCheckpointall versionsCheckpoint Quantum Spark 1590
HWCheckpointall versionsCheckpoint Quantum Spark 1595r
HWCheckpointall versionsCheckpoint Quantum Spark 1600
HWCheckpointall versionsCheckpoint Quantum Spark 1800
HWCheckpointall versionsCheckpoint Quantum Spark 1900
HWCheckpointall versionsCheckpoint Quantum Spark 2000
HWCheckpointall versionsCheckpoint Quantum Spark 2530
HWCheckpointall versionsCheckpoint Quantum Spark 2550
HWCheckpointall versionsCheckpoint Quantum Spark 2560
HWCheckpointall versionsCheckpoint Quantum Spark 2570
HWCheckpointall versionsCheckpoint Quantum Spark 2580
HWCheckpointall versionsCheckpoint Quantum Spark 2590
HWCheckpointall versions
CISA KEV — detailsi
- Vendori
- Check Point
- Producti
- Security Gateway
- Added to KEVi
- June 8, 2026
- Remediation deadline (US Federal)i
- June 11, 2026(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Related vulnerabilities
Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Secu...
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an a...
For an authenticated end-user the portal may run a script while attempting to display a directory or some file...
In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unex...
The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Cli...