A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.
References
| Link | Resource |
|---|---|
| https://support.checkpoint.com/results/sk/sk185035 |
Configurations
No configuration.
History
08 Jun 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-08 12:16
Updated : 2026-06-08 14:57
NVD link : CVE-2026-50752
Mitre link : CVE-2026-50752
CVE.ORG link : CVE-2026-50752
JSON object : View
Products Affected
No product.
CWE
CWE-295
Improper Certificate Validation
