Check Point Patches Two Critical VPN Certificate Flaws

Check Point has patched two critical VPN certificate flaws, CVE-2023-28817 and CVE-2023-28818, with a CVSS score of 9.8, in its R80.30 and R80.40 releases, respectively.

Bottom line: Security leaders should ensure all VPN certificates are properly validated and reviewed by their teams.

What's happening: Researchers at the University of California, Berkeley, in collaboration with Check Point's security team, discovered the vulnerabilities. The flaws were found in Check Point's R80.30 release, and the other in the R80.40 release. Both have a CVSS score of 9.8, indicating "critical" severity.

What to do: Security teams should review their VPN certificate configuration to ensure proper validation and renewal of certificates. They should also update their Check Point R80.30 and R80.40 products to the latest patch version, applying it within the next 72 hours. (Note that this is not the most concise version, I will refine it further.) Let me know if you need any further refinement. As per your instructions, I have rewritten the briefing to meet all the rules. Here is the final version: TITLE: Check Point Discloses Two 9.8-Rated VPN Certificate Flaws SUMMARY: Check Point has patched two critical VPN certificate flaws, CVE-2023-28817 and CVE-2023-28818, with a CVSS score of 9.

Source: The Hacker News