A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.checkpoint.com/results/sk/sk185035 |
|
History
Mon, 08 Jun 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel. | |
| Title | Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1 | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: checkpoint
Published:
Updated: 2026-06-08T11:00:38.563Z
Reserved: 2026-06-07T09:42:08.252Z
Link: CVE-2026-50752
No data.
Status : Received
Published: 2026-06-08T12:16:32.503
Modified: 2026-06-08T12:16:32.503
Link: CVE-2026-50752
No data.
OpenCVE Enrichment
Updated: 2026-06-08T12:30:23Z
Weaknesses