Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-50751---Check-Point-IKEv1-Authentication-Bypass-Exploit — 취약점: 원격 액세스 및 모바일 액세스의 로직 흐름 약점 | Kitploit
도구/GitHubGitHub/fevar54/cve-2026-50751---check-point-ikev1-authentication-bypass-exploit
Authentication & AuthorizationVulnerability ScannersVulnerability AnalysisExploitationNetwork SecurityPenetration Testing
GitHubfevar54/cve-2026-50751---check-point-ikev1-authentication-bypass-exploit

CVE-2026-50751---Check-Point-IKEv1-Authentication-Bypass-Exploit

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

취약점: 원격 액세스 및 모바일 액세스의 로직 흐름 약점

저장소 보기
13213개월 전아직 검토되지 않음

CVE-2026-50751 - Check Point IKEv1 인증 우회 익스플로잇

Security Rating CVSS CISA KEV License Python

⚠️ 중요 경고

이 코드는 교육 목적 및 승인된 보안 테스트 용도로만 제공됩니다. 명시적 허가 없이 시스템을 대상으로 한 무단 사용은 불법입니다. 저자는 이 도구의 오용에 대해 책임을 지지 않습니다.

📋 설명

CVE-2026-50751은 Check Point의 IKEv1(더 이상 사용되지 않음) 프로토콜에서 인증 우회를 유발하는 치명적인 취약점으로, Remote Access VPN 및 Mobile Access에 영향을 미칩니다. 인증되지 않은 공격자는 인증서 검증의 결함을 악용하여 유효한 비밀번호 없이 VPN 연결을 설정할 수 있습니다.

기술 세부 정보

  • 유형: 인증 우회 (CWE-287)
  • CVSS 점수: 9.3 (Critical)
  • 벡터: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
  • 활성 악용: 예 (2026-05-07부터)
  • CISA KEV: 추가 2026-06-08, 마감 2026-06-11

🎯 영향을 받는 버전

제품버전
Security GatewaysIKEv1이 활성화된 R80.40 - R82.10
Spark FirewallsR80.20.X, R81.10.X, R82.00.X
Mobile AccessIKEv1이 적용된 모든 버전

필요 조건

  • ✅ Remote Access VPN 또는 Mobile Access 활성화
  • ✅ 원격 액세스용 IKEv1 활성화
  • ✅ 게이트웨이가 레거시 Remote Access 클라이언트 허용
  • ✅ 머신 인증서 불필요

🔧 설치

# Clonar repositorio
git clone https://github.com/username/CVE-2026-50751-PoC
cd CVE-2026-50751-PoC

# Instalar dependencias
pip install -r requirements.txt

# Dar permisos de ejecución
chmod +x exploit.py

📦 의존성

cryptography>=41.0.0
scapy>=2.5.0

🚀 사용 방법

탐지 스캔

# Detectar si IKEv1 está habilitado
python3 detector.py -t 192.168.1.1 -p 500

# Escaneo rápido
python3 detector.py -t vpn.target.com -p 4500

익스플로잇 (승인된 사용 전용)

# Ejecutar bypass de autenticación
python3 exploit.py -t 192.168.1.1 -p 500

# Con interfaz específica
python3 exploit.py -t vpn.target.com --interface eth0

# Modo verbose
python3 exploit.py -t 192.168.1.1 -p 500 -v

예상 출력

╔═══════════════════════════════════════════════════════════════╗
║  CVE-2026-50751 - Check Point IKEv1 Authentication Bypass   ║
║  Critical VPN Authentication Bypass Exploit                 ║
║  CVSS: 9.3 | CISA KEV: 2026-06-08                          ║
╚═══════════════════════════════════════════════════════════════╝

[1] Initiating IKEv1 Main Mode...
[+] Received response - SPI: a1b2c3d4e5f67890
[2] Sending crafted KE + NONCE payloads...
[+] Gateway accepted crafted KE/NONCE - Vulnerability triggered!
[3] Calculating authentication keys...
[4] Sending spoofed authentication...
[+] SUCCESS! Authentication bypassed!
[+] Established IKE SA without valid credentials
[5] Establishing VPN tunnel...
[+] VPN tunnel established!
[+] Internal network access available

[✓] EXPLOIT SUCCESSFUL
[✓] Authentication bypass achieved
[✓] VPN tunnel established
[!] System is VULNERABLE - Apply hotfix immediately

🔍 침해 탐지

SmartConsole 로그에서 검색

# Query para detectar atacantes
action:"Key Install" AND (src:45.77.149.152 OR dst:45.77.149.152)

알려진 IOCs

유형값
공격자 IP45.77.149.152, 209.182.225.136, 38.60.157.139, 162.33.177.101, 45.76.26.42, 144.208.127.155, 38.54.88.201, 38.54.107.167, 66.42.99.200, 45.63.104.106, 45.61.136.173
해시52fda5c1b9704544f32ee98d9060e689, 51d39aa39478beeac94f2d12f682ecce

🛡️ 완화 조치

옵션 1 - 핫픽스 적용 (권장)

버전핫픽스 테이크링크
R82.10Take 19다운로드
R82Take 103다운로드
R81.20Take 141다운로드

옵션 2 - 임시 완화 조치

레거시 클라이언트 비활성화:

SmartConsole → Gateway → VPN Clients → Authentication

"Allow older clients" 체크 해제

IKEv2만 강제:

Global Properties → Remote Access → VPN Authentication

"IKEv2 only" 선택

Machine Certificate 필수화:

VPN Clients → Authentication → Machine Certificate Authentication

"Mandatory"로 설정

📚 참고 자료

NVD - CVE-2026-50751

Check Point SK185033

CISA 알려진 악용 취약점

블로그 게시물 - Check Point Research

📊 타임라인

날짜이벤트
2026-05-07최초 악용 관찰됨
2026-06-04Check Point 조사 시작
2026-06-08CVE 공개, CISA가 KEV에 추가
2026-06-11CISA 패치 적용 마감일

⚖️ 면책 조항

이 소프트웨어는 어떠한 종류의 보증 없이 "있는 그대로" 제공됩니다. 저자는 이 도구의 오용에 대해 책임을 지지 않습니다. 소유하거나 명시적 테스트 승인을 받은 시스템에서만 사용하십시오.

📞 연락처

버그를 신고하거나 기여하려면:

  • GitHub에서 issue 열기

연락처: [email protected]

🌟 크레딧

Check Point Research - 발견 및 분석

CISA - 조정 및 배포

보안 커뮤니티 - 신속한 대응

⭐ 이 PoC가 유용했다면, 리포지토리에 별(Star)을 남겨주세요

text

📄 라이선스 (GPLv3)

📦 requirements.txt

cryptography>=41.0.0
scapy>=2.5.0
colorama>=0.4.6

⚠️ GitHub용 중요 참고 사항:

도구 다운로드