CVE-2026-48132 Details
Description
The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic).
A denial-of-service vulnerability has been identified in Check Point Security Gateways and Spark Firewall. The issue arises because the Security Gateway improperly validates length values in certain IKE packets when NAT-T is used over UDP port 4500. This flaw allows a specially crafted or malformed packet to disrupt the VPN processing service, causing it to terminate unexpectedly. As a result, there is a temporary interruption in VPN negotiations and traffic.
To address this vulnerability, users can enable the IPS protection 'IKE Improper Length Validation' in Protection mode. For Security Gateways, the fix is included in the Jumbo Hotfix Accumulator for R82.10 starting from Take 19, for R82 starting from Take 103, and for R81.20 starting from Take 141. For Spark Firewalls, the fix is available in R81.10.17 and R82.00.10.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.checkpoint.com/results/sk/sk184982 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | New CVE Received | [email protected] |