Rule Category

SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in the network.

Alert Message

SERVER-OTHER Check Point Remote Access VPN IKEv1 authentication bypass attempt

Rule Explanation

This rule looks for a specific IKEv1 authentication sequence that includes a known magic identifier followed by a byte pattern indicating the vulnerable flag. Successful exploitation allows an unauthenticated client to gain access to the VPN service.

What To Look For

This rule fires on attempts to bypass authentication in Check Point Remote Access VPN IKEv1 servers.

Known Usage

No public information

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application

Rule Categories::Server::Other

Vulnerability::Severity::Critical

Vulnerability::Severity::High

CVE

Additional Links

Rule Vulnerability

Authentication Bypass

An Authentication Bypass occurs when there is a way to avoid providing user credentials to a system before performing restricted operations on said system.

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2026-50751
Loading description