Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-5635


Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not properly maintain the state of password failures, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by entering password guesses within multiple Unlock.exe processes that are running simultaneously.


Published

2013-11-30T11:43:54.570

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 3.3 (LOW)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

3.4

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-255

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application checkpoint endpoint_security e80 Yes
Application checkpoint endpoint_security e80.10 Yes
Application checkpoint endpoint_security e80.20 Yes
Application checkpoint endpoint_security e80.30 Yes
Application checkpoint endpoint_security e80.40 Yes
Application checkpoint endpoint_security e80.41 Yes
Application checkpoint endpoint_security e80.50 Yes

References