CVE-2013-5636

Unlock.exe in Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not associate password failures with a device ID, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by overwriting DVREM.EPM with a copy of itself after each few password guesses.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:checkpoint:endpoint_security:e80:-:vpn_blade:*:*:*:*:*
cpe:2.3:a:checkpoint:endpoint_security:e80.10:-:vpn_blade:*:*:*:*:*
cpe:2.3:a:checkpoint:endpoint_security:e80.20:-:vpn_blade:*:*:*:*:*
cpe:2.3:a:checkpoint:endpoint_security:e80.30:-:vpn_blade:*:*:*:*:*
cpe:2.3:a:checkpoint:endpoint_security:e80.40:-:vpn_blade:*:*:*:*:*
cpe:2.3:a:checkpoint:endpoint_security:e80.41:-:vpn_blade:*:*:*:*:*
cpe:2.3:a:checkpoint:endpoint_security:e80.50:-:vpn_blade:*:*:*:*:*

History

21 Nov 2024, 01:57

Type Values Removed Values Added
References () http://www.digitalsec.net/stuff/explt+advs/CheckPoint_EndPoint_EPM_Explorer.txt - () http://www.digitalsec.net/stuff/explt+advs/CheckPoint_EndPoint_EPM_Explorer.txt -
References () https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk96589 - Patch, Vendor Advisory () https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk96589 - Patch, Vendor Advisory

Information

Published : 2013-11-30 11:43

Updated : 2024-11-21 01:57


NVD link : CVE-2013-5636

Mitre link : CVE-2013-5636

CVE.ORG link : CVE-2013-5636


JSON object : View

Products Affected

checkpoint

  • endpoint_security
CWE
CWE-255

Credentials Management Errors