Check Point VPN zero-day exploited by Qilin ransomware affiliates
Check Point has disclosed a critical authentication bypass in its Remote Access VPN, Mobile Access and Spark Firewall products. The flaw lets an unauthenticated attacker open a VPN session with no valid credentials on gateways using the deprecated IKEv1 key exchange. Check Point $CHKP says it has been exploited since early May and now links the attacks to Qilin ransomware affiliates.
Check Point $CHKP has disclosed a critical authentication bypass affecting its Remote Access VPN, Mobile Access and Spark Firewall products, scored 9.3. On systems using the deprecated IKEv1 key exchange that accept legacy clients without a machine certificate, an unauthenticated attacker can open a full VPN session with no valid credentials. Check Point says the bug has been exploited in the wild since early May, with activity rising in June, and links the attacks to affiliates of the Qilin ransomware gang. So far a few dozen organizations worldwide have been hit. A hotfix is out and CISA has ordered federal agencies to patch within three days.