CVE-2022-23746: Check Point SSL Network Extender

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords.

Affected products

  • Check Point SSL Network Extender: version r80.20 only; version r80.20sp only; version r80.30 only; version r80.30sp only; version r80.40 only; version r81 only; …

Published 2022-11-30. Last modified 2026-06-17.