Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.
From 神龙GPT (AIGC)
Check Point Firewall-1 允许远程攻击者绕过 FTP 服务器的端口访问限制,因为它迫使服务器发送恶意数据包,而这些数据包被Firewall-1误解为客户端的 PASV 尝试所返回的合法的 227 响应。