> Source: [sk149892](https://support.checkpoint.com/results/sk/sk149892)

# sk149892 - Check Point Response to CVE-2019-8456 - unauthorized VPN access to internal networks via IKEv2 tunnel 

| Property | Value |
|----------|-------|
| Solution ID | sk149892 |
| Date Created | 2019-03-26 |
| Last Modified | 2025-02-09 |
| Technical Level | General |

## Symptoms

- In some less common conditions, Check Point IKEv2 IPsec VPN up to R80.30 may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server.

## Solution

**Important Notes:**

* R77.x versions are not affected because they use a different code.
* The vulnerability is relevant to IKEv2 only.
* The issue is relevant to Security Gateways only and has no effect on Security Management Servers.

This problem was fixed. The fix is included starting from:

* **[Check Point R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk144293)**
* **[Jumbo Hotfix Accumulator for R80.20 with Gaia 3.10 for CloudGuard and Open Server Security Gateways](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk146212)**
* **[Check Point R80.20 Jumbo Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) from Take 73**
* **[Check Point R80.10 Jumbo Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116380&partition=General&product=Security) from Take 203**

Check Point recommends to always [upgrade to the most recent version](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=446).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
