CVE-2014-8951
Estado: ModificadaAlta (7.1)—
Unspecified vulnerability in Check Point Security Gateway R75, R76, R77, and R77.10, when UserCheck is enabled and the (1) Application Control, (2) URL Filtering, (3) DLP, (4) Threat Emulation, (5) Anti-Bot, or (6) Anti-Virus blade is used, allows remote attackers to cause a denial of service (fwk0 process crash, core dump, and restart) via a redirect to the UserCheck page.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.55%
- Percentil entre todas las CVEs puntuadas: 74
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
- http://secunia.com/advisories/58487
- http://www.securityfocus.com/bid/67993
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98761
- https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100505
- http://secunia.com/advisories/58487
- http://www.securityfocus.com/bid/67993
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98761
- https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100505
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-8951",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.1,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-11-16T17:59:07.020",
"references": [
{
"url": "http://secunia.com/advisories/58487",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/67993",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/98761",
"source": "cve@mitre.org"
},
{
"url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100505",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/58487",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/67993",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/98761",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100505",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Unspecified vulnerability in Check Point Security Gateway R75, R76, R77, and R77.10, when UserCheck is enabled and the (1) Application Control, (2) URL Filtering, (3) DLP, (4) Threat Emulation, (5) Anti-Bot, or (6) Anti-Virus blade is used, allows remote attackers to cause a denial of service (fwk0 process crash, core dump, and restart) via a redirect to the UserCheck page."
},
{
"lang": "es",
"value": "Una vulnerabilidad sin especificar en Check Point Security Gateway R75, R76, R77, y R77.10, cuando el UserCheck está activado y (1) Application Control, (2) URL Filtering, (3) DLP, (4) Threat Emulation, (5) Anti-Bot, o (6) Anti-Virus blade está en uso, permite a atacantes remotos provocar una denegación de servicio (caída del proceso fwk0, volcado de memoria y reinicio) a través de una redirección a la página de UserCheck."
}
],
"lastModified": "2026-06-17T00:17:34.277",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:checkpoint:security_gateway:r75:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A489A6D-EB07-42CD-A831-4BFFC131DB57"
},
{
"criteria": "cpe:2.3:a:checkpoint:security_gateway:r76:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A76290E-924C-46CC-ABD5-B4AB193A7E5A"
},
{
"criteria": "cpe:2.3:a:checkpoint:security_gateway:r77:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "11B8D136-7127-444F-BB8C-196A76AC764A"
},
{
"criteria": "cpe:2.3:a:checkpoint:security_gateway:r77.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6BCFFDF7-6382-40A0-A078-759EE09B0252"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}