oM noM Security Feeds cve
vulnerability context

CVE-2007-3489

EPSS 87%

Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as demonstrated by a request with the swuuser and swupass parameters, which adds an administrator account. NOTE: the CSRF attack has no timing window because there is no logout capability in the management interface.

Published 2007-06-29 · last modified 2026-06-16

details

CISA KEV status
Not in catalog
EPSS
87% percentile (score 0.0328)
OTX pulses
0 total, 0 recent

source mentions 1

source consensus

  • Bluesky:@cyberhub.blog
Want the 3-bullet summary of CVE-2007-3489, plus webhook alerts when KEV is updated? Pro is $10/mo.