The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configuration information for the protected network without authentication.
https://exchange.xforce.ibmcloud.com/vulnerabilities/6857
https://euvd.enisa.europa.eu/vulnerability/EUVD-2001-1284
http://www.securityfocus.com/bid/3058