<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH vulnerability detected, please verify. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27610#M2179</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Last update on CP in the link you have included is from&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;15-May-2014. The reclassification happen on 10/10/2017.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 03 Feb 2018 20:24:00 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2018-02-03T20:24:00Z</dc:date>
    <item>
      <title>SSH vulnerability detected, please verify.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27608#M2177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've been using Nmap vulners plugin for the past months and it seem to be pretty accurate, so I am a bit concerned with the results of today's scan of my lab network:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62832_pastedImage_1.png" style="width: 620px; height: 595px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nessus sees mostly nuisance vulnerabilities and does not complain about&amp;nbsp;&amp;nbsp;CVE-2006-5051:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62833_pastedImage_4.png" style="width: 620px; height: 292px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The rating of 9.3 is listed here:&amp;nbsp;&amp;nbsp;&lt;A class="link-titled" href="https://nvd.nist.gov/vuln/detail/CVE-2006-5051" title="https://nvd.nist.gov/vuln/detail/CVE-2006-5051"&gt;NVD - CVE-2006-5051&lt;/A&gt;&amp;nbsp;it was modified on 10/10/2017.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Feb 2018 20:01:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27608#M2177</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-02-03T20:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: SSH vulnerability detected, please verify.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27609#M2178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem with most vulnerability scanners is they just say "On, you're running OpenSSH 4.3" and therefore must be vulnerable to this laundry list of CVEs without actually checking if it's a real issue or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even though we're still running OpenSSH 4.3, we've patched the issue.&lt;/P&gt;&lt;P&gt;Refer to:&amp;nbsp;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61744" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61744"&gt;Check Point response to OpenSSH vulnerabilities: CVE-2006-5051 and CVE-2006-4924&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Feb 2018 20:20:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27609#M2178</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-03T20:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSH vulnerability detected, please verify.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27610#M2179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Last update on CP in the link you have included is from&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;15-May-2014. The reclassification happen on 10/10/2017.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Feb 2018 20:24:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27610#M2179</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-02-03T20:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSH vulnerability detected, please verify.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27611#M2180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That being said, the statement is still valid, maybe SK date should simply be updated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Feb 2018 20:25:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27611#M2180</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-02-03T20:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSH vulnerability detected, please verify.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27612#M2181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NVD may have changed the classification for the problem in October 2017, but the underlying issue (and fix) is the same as it was back in 2006 when the issue was first discovered.&lt;/P&gt;&lt;P&gt;Thus there's nothing to update in the SK.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Feb 2018 20:34:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27612#M2181</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-03T20:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: SSH vulnerability detected, please verify.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27613#M2182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very well. Can you delete this post?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Feb 2018 20:36:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27613#M2182</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-02-03T20:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSH vulnerability detected, please verify.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27614#M2183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Don't see a reason to delete it as the general topic is bound to come up again.&lt;/SPAN&gt;&lt;P class=""&gt;It sure did in the days I worked in the TAC &lt;ABBR&gt;&lt;SPAN aria-label="Mischief" class="emoticon-inline emoticon_mischief" style="height:16px;width:16px;"&gt;&lt;/SPAN&gt;&lt;/ABBR&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Feb 2018 23:58:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSH-vulnerability-detected-please-verify/m-p/27614#M2183</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-03T23:58:41Z</dc:date>
    </item>
  </channel>
</rss>

