When specially crafted CCP packets are sent to all Check Point ClusterXL cluster members, it can trigger confusion about the state of its peer(s) and leave everything in a Ready/Standby state. This leads to a denial of service where none of the cluster members will forward network traffic. Proof of concept code included…. When specially crafted CCP packets are sent to all Check Point ClusterXL cluster members, it can trigger confusion about the state of its peer(s) and leave everything in a Ready/Standby state. This leads to a denial of service where none of the cluster members will forward network traffic. Proof of concept code included.

Read more http://packetstormsecurity.com/files/123129/clusterxl-dos.tgz