SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in the network.
SERVER-OTHER Check Point Remote Access VPN IKEv1 authentication bypass attempt
This rule looks for a specific IKEv1 authentication sequence that includes a known magic identifier followed by a byte pattern indicating the vulnerable flag. Successful exploitation allows an unauthenticated client to gain access to the VPN service.
This rule fires on attempts to bypass authentication in Check Point Remote Access VPN IKEv1 servers.
No public information
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Rule Categories::Server::Other
Vulnerability::Severity::Critical
Vulnerability::Severity::High
Authentication Bypass
An Authentication Bypass occurs when there is a way to avoid providing user credentials to a system before performing restricted operations on said system.
CVE-2026-50751 |
Loading description
|