CVE-2026-85103

Summary

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

Affected Software

VendorProductVersion RangeStatus
checkpointQuantum Security GatewayR82.10 with Jumbo Hotfix Take 43 or belowaffected
checkpointQuantum Security GatewayR82 with Jumbo Hotfix Take 125 or belowaffected
checkpointQuantum Security GatewayR81.20 with Jumbo Hotfix Take 165 or belowaffected
checkpointQuantum Security ManagementR82.10 with Jumbo Hotfix Take 43 or belowaffected
checkpointQuantum Security ManagementR82 with Jumbo Hotfix Take 125 or belowaffected
checkpointQuantum Security ManagementR81.20 with Jumbo Hotfix Take 165 or belowaffected

Weaknesses

  • CWE-122: CWE-122: Heap-based Buffer Overflow.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References