CVE-2022-23746: Check Point SSL Network Extender
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords.
Affected products
- Check Point SSL Network Extender: version r80.20 only; version r80.20sp only; version r80.30 only; version r80.30sp only; version r80.40 only; version r81 only; …
Published 2022-11-30. Last modified 2026-06-17.