> Source: [sk170422](https://support.checkpoint.com/results/sk/sk170422)

# sk170422 - Check Point Response to CVE-2020-28041 - NAT Slipstreaming

| Property | Value |
|----------|-------|
| Solution ID | sk170422 |
| Date Created | 2020-11-10 |
| Last Modified | 2025-02-09 |
| Technical Level | General |
| Products | Security Gateway, Spark Firewall (Locally Managed) |
| Versions | R82, R81.20, R81.10 (EOS), R81.10.X, R81 (EOS) |
| OS | Gaia |

## Symptoms

- * On October 31, 2020, a new RCE vulnerability named NAT Slipstreaming was published by Samy Kamkar at <https://samy.pl/slipstream/>.

* The vulnerability [CVE-2020-28041](https://www.cve.org/CVERecord?id=CVE-2020-28041) was reported about Netgear Nighthawk R7000.

  Yet, Check Point started looking into it to make sure that we are not affected as well.

## Cause

The attack involves several vectors - Local IP disclosure, max MTU (UDP and TCP) calculation and leveraging a SIP parser weakness in fragmented HTTP packets which enables to "Slipstream" a legitimate SIP connection in an HTTP POST request generated by the victim's browser.  

The full description of the attack can be read at: <https://samy.pl/slipstream/>

## Solution

Check Point Security Gateways (as well as the rest of Check Point products) are not vulnerable to the NAT Slipstreaming attack.  

Check Point gateways handle the traffic as a whole and therefore this would result with an invalid SIP packet. This, of course, we block as we expect a specific format that does not apply to this injection technique.  

You can use [Check Point IPS protection "CPAI-2020-1185"](https://www.checkpoint.com/defense/advisories/public/2020/CPAI-2020-1185.html) to protect vulnerable NAT devices behind Check Point Security Gateway.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
