Madrid, December 12, 2005 - A vulnerability has been detected in CheckPoint VPN-1 SecureClient that could allow the security policy to be disabled, according to a bulletin released by SecurityTracker.
The security problem lies in SecureClient trusting in the local copy of the policy file (lcal.scv) to check client integrity before allowing it to connect to internal networks via VPN. Users with write access to the file can bypass this check and continuously replace the file with a modified file.
If this vulnerability is successfully exploited, when the SecureClient is started, the original security policy will not be enforced.
Oxygen3 24h-365d
by Panda Software
Member of IVSZ

Member of SZEK

Acer Affinity Gold partner

Dell Registered Partner
![]()
OKI System Shinrai Partner

XEROX Viszonteladó

APC megbízható szállító

EATON Authorized Partner

Cisco partner

Symantec Software Partner

ESET Partner
![]()
FUJITSU partner

LENOVO Premium Partner

IBM Business Partner

PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel