> Source: [sk181386](https://support.checkpoint.com/results/sk/sk181386)

# sk181386 - Check Point response to the TunnelCrack vulnerability

| Property | Value |
|----------|-------|
| Solution ID | sk181386 |
| Date Created | 2023-08-10 |
| Last Modified | 2023-10-11 |
| Technical Level | General |
| Products | Security Gateway, Endpoint Security |
| Versions | R82.10, R82, R81.20, Cloud, E89.X, E88.X |
| OS | Windows, macOS, Android, iOS |

## Solution

**Table of Contents:**

* Background
* Check Point response
* VPN Client Modes and Possible Attack Prevention
* Vulnerability of Check Point Remote Access VPN Clients to the LocalNet and ServerIP Attacks

<br />

### Background {#1}

TunnelCrack is a combination of two widespread security vulnerabilities in VPN that can cause a broad range of Remote Access VPN clients to leak user traffic outside the protected encryption tunnels.

The two attacks, "LocalNet" and "ServerIP", stem from how Remote Access VPN clients configure the underlying operating system to route traffic through VPN tunnels by updating the operating system's IP routing tables.

It is possible for an attacker to manipulate exceptions in the routing scheme by using spoofed DNS responses and rogue Wi-Fi Access Points, achieving unencrypted network traffic leak even when a Remote Access VPN connection is active.

The issues are summarized in these CVEs:

|---------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------|------------|
| CVE                                                                             | Brief Description                                                                           | CVSS Score |
| [CVE-2023-36672](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-36672) | LocalNet attack resulting in leakage of traffic in plaintext.                               | 6.8        |
| [CVE-2023-35838](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35838) | LocalNet attack resulting in the blocking of traffic.                                       | 3.1        |
| [CVE-2023-36673](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-36673) | ServerIP attack, combined with DNS spoofing, that can leak traffic to arbitrary IP address. | 7.4        |
| [CVE-2023-36671](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-36671) | ServerIP attack where only traffic to the real IP address of the VPN server can be leaked.  | 3.1        |

<br />

### Check Point response {#2}

We believe, based on our most recent examinations, that these reports do not have a real impact on Check Point Remote Access VPN clients.

Given default configurations and additional factors, this vulnerability is complicated to exploit and in any way not creating a risk to corporate data, resources, or employee credentials disclosure when using standard configuration of Check Point Remote Access VPN clients.

As always, Check Point will continue to monitor any report and, when necessary, create the relevant protections, as well as any other relevant preventive measures.

<br />

### VPN Client Modes and Possible Attack Prevention {#3}

Check Point Remote Access VPN clients can work in two modes:

|----------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| VPN Client Mode            | VPN Client Behavior                                                                                                                                                        | Prevention of the LocalNet attack                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | Prevention of the ServerIP attack                                                                                                                                                                                                                         |
| Hub Mode (this is default) | The VPN client encrypts and sends all traffic through a VPN Gateway.                                                                                                       | Available options: 1. Make sure to disable the "Exclude local network" option (see [Remote Access VPN Clients for Windows Administration Guide](https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Excluding-Local-Networks-from-Hub-Mode.htm)). Disadvantage - make resources on local network unavailable (printers, cameras, scanners, etc.). 2. It is possible to use a Firewall and block non-encrypted traffic to a local network. To mitigate the impact, allow access only to essential resources on the local network. To prevent the "LocalNet" attack completely, completely disable the access to resources from the local network. | The ServerIP attack flavor is not possible out-of-the-box because of how VPN client builds routing table. The VPN client always excludes from VPN tunnel real IP address of the VPN Gateway. Traffic to a fake IP address is always routed to VPN tunnel. |
| Split Tunnel Mode          | The VPN client encrypts only traffic which is targeted to resources within Encryption Domain (set of networks behind the VPN Gateway which should be accessible over VPN). | Route to an internal resource IP address always has high priority, and traffic to this IP address will go through the VPN tunnel.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | The ServerIP attack flavor is not possible out-of-the-box because of how VPN client builds routing table. The VPN client always excludes from VPN tunnel real IP address of the VPN Gateway. Traffic to a fake IP address is always routed to VPN tunnel. |

<br />

### Vulnerability of Check Point Remote Access VPN Clients to the LocalNet and ServerIP Attacks {#4}

The table below is provided for the default configuration in the corresponding Software Blade and the Remote Access VPN client.

Enter the string to filter this table:

|-------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------|
| Check Point Remote Access VPN Client                        | Vulnerability to the LocalNet Attack                                                                                          | Vulnerability to the ServerIP Attack                                                                                          |
| Harmony Connect                                             | Safe (v1.4.8 and above)                                                                                                       | Safe (v1.4.8 and above)                                                                                                       |
| Harmony Endpoint                                            | Safe ![](https://sc1.checkpoint.com/sc/images/sk_images/Warning.png)                                                          | Safe                                                                                                                          |
| Endpoint Security Client suite                              | Safe ![](https://sc1.checkpoint.com/sc/images/sk_images/Warning.png)                                                          | Safe                                                                                                                          |
| Endpoint Security VPN                                       | Safe ![](https://sc1.checkpoint.com/sc/images/sk_images/Warning.png)                                                          | Safe                                                                                                                          |
| Check Point Mobile                                          | Safe ![](https://sc1.checkpoint.com/sc/images/sk_images/Warning.png)                                                          | Safe                                                                                                                          |
| SecuRemote                                                  | Safe ![](https://sc1.checkpoint.com/sc/images/sk_images/Warning.png)                                                          | Safe                                                                                                                          |
| SSL Network Extender - connected to a Mobile Access Gateway | Safe                                                                                                                          | Vulnerable (all SNX versions) Check Point plans to release the fixed version in Q4 2023                                       |
| SSL Network Extender - connected to a VPN Gateway           | Safe                                                                                                                          | Safe                                                                                                                          |
| Capsule VPN plugin for Windows                              | Vulnerable (all plugin versions) Check Point plans to release the fixed version in Q1 2024                                    | Vulnerable (all plugin versions) Check Point plans to release the fixed version in Q1 2024                                    |
| Capsule Connect for iOS                                     | Vulnerable by default (all app versions), but configurable See [sk181399](https://support.checkpoint.com/results/sk/sk181399) | Vulnerable by default (all app versions), but configurable See [sk181399](https://support.checkpoint.com/results/sk/sk181399) |
| Capsule VPN for Android                                     | Safe                                                                                                                          | Vulnerable by default (all app versions), but configurable See [sk181416](https://support.checkpoint.com/results/sk/sk181416) |

{#Unique_IDTable}

![](https://sc1.checkpoint.com/sc/images/sk_images/Warning.png) If an administrator enables the Hub Mode and enables the option "Exclude local network" (see [Remote Access VPN Clients for Windows Administration Guide](https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Excluding-Local-Networks-from-Hub-Mode.htm)), then the Remote Access VPN client is vulnerable to the "LocalNet" attack by design.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
