<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Find status of IPS based on CVE identifiers? in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Find-status-of-IPS-based-on-CVE-identifiers/m-p/144341#M6642</link>
    <description>&lt;P&gt;As noted in my IPS/AV/ABOT Immersion class below, certain IPS Protection fields are not searchable from the SmartConsole, which almost certainly means they are not searchable through the API either.&amp;nbsp; Unfortunately you'd have to iterate through all the protections like Gunter mentioned to search for the CVE that way.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cve_search.png" style="width: 984px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15789i8BD021DC90F03DFA/image-size/large?v=v2&amp;amp;px=999" role="button" title="cve_search.png" alt="cve_search.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Mar 2022 18:41:35 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2022-03-21T18:41:35Z</dc:date>
    <item>
      <title>Find status of IPS based on CVE identifiers?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Find-status-of-IPS-based-on-CVE-identifiers/m-p/144300#M6640</link>
      <description>&lt;P&gt;I have a re-occuring need to use the API to find the status of a particular CVE protection and find it for many customers.&lt;/P&gt;
&lt;P&gt;But from the API manuals I have not been able to find a way to obtain that information. Am I missing something in the manual or is it not implemented in the API?&lt;/P&gt;
&lt;P&gt;What would be the best way to find the status of&amp;nbsp;CVE-2021-44228 with the API for example?&lt;/P&gt;
&lt;P&gt;Regards, Hugo.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 13:48:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Find-status-of-IPS-based-on-CVE-identifiers/m-p/144300#M6640</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2022-03-21T13:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: Find status of IPS based on CVE identifiers?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Find-status-of-IPS-based-on-CVE-identifiers/m-p/144315#M6641</link>
      <description>&lt;P&gt;You can show protections with&amp;nbsp;&lt;SPAN&gt;name or uid as reference only:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;mgmt_cli show threat-protection name "&lt;/SPAN&gt;&lt;SPAN&gt;FTP Commands"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;listing the details like&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;protection-type: "Core"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;follow-up: false&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;industry-reference:&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- "CAN-2002-0610"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- "CAN-2001-0755"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- "CAN-2002-0606"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- "CAN-2001-0263"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You would have to cycle thru all UIDs and build a list...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 15:55:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Find-status-of-IPS-based-on-CVE-identifiers/m-p/144315#M6641</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-21T15:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Find status of IPS based on CVE identifiers?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Find-status-of-IPS-based-on-CVE-identifiers/m-p/144341#M6642</link>
      <description>&lt;P&gt;As noted in my IPS/AV/ABOT Immersion class below, certain IPS Protection fields are not searchable from the SmartConsole, which almost certainly means they are not searchable through the API either.&amp;nbsp; Unfortunately you'd have to iterate through all the protections like Gunter mentioned to search for the CVE that way.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cve_search.png" style="width: 984px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15789i8BD021DC90F03DFA/image-size/large?v=v2&amp;amp;px=999" role="button" title="cve_search.png" alt="cve_search.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 18:41:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Find-status-of-IPS-based-on-CVE-identifiers/m-p/144341#M6642</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-03-21T18:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Find status of IPS based on CVE identifiers?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Find-status-of-IPS-based-on-CVE-identifiers/m-p/144351#M6644</link>
      <description>&lt;P&gt;It depends what you want to look at, but starting MGMT API version 1.6 (R80.40) you can use &lt;EM&gt;filter &lt;/EM&gt;parameter. This call will show you all that you need to know. Take out the &lt;EM&gt;show-ips-additional-properties&lt;/EM&gt; and/or &lt;EM&gt;show-profiles&lt;/EM&gt; parameters if you don't need their outputs. E.g.:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/#cli/show-threat-protections~v1.6%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/#cli/show-threat-protections~v1.6%20&lt;/A&gt;&lt;/P&gt;
&lt;LI-CODE lang="python"&gt;# mgmt_cli -r true show threat-protections filter 'CVE-2021-44228' limit 1 details-level full show-ips-additional-properties true show-profiles true -f json&lt;/LI-CODE&gt;
&lt;P&gt;Good luck!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 19:38:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Find-status-of-IPS-based-on-CVE-identifiers/m-p/144351#M6644</guid>
      <dc:creator>Art_Zalenekas</dc:creator>
      <dc:date>2022-03-21T19:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Find status of IPS based on CVE identifiers?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Find-status-of-IPS-based-on-CVE-identifiers/m-p/144614#M6666</link>
      <description>&lt;P&gt;I found the cause. I used login seperatly but on the wrong domain. Took the wrong script as template and forgot all about the domain in the login. (It was the script to add all of our employees that need access to the list of administrators. But that is no the domain you usualy work in.&lt;/P&gt;
&lt;P&gt;So I need to do some clever scripting now to fecth the right list and parse them for a loop.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 16:10:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Find-status-of-IPS-based-on-CVE-identifiers/m-p/144614#M6666</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2022-03-23T16:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: Find status of IPS based on CVE identifiers?</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/Find-status-of-IPS-based-on-CVE-identifiers/m-p/178808#M7633</link>
      <description>&lt;P&gt;Just to follow up on this old thread, for IPS Protections the "Industry Reference" field which normally contains CVE numbers is now searchable in the latest versions of the R81.10 SmartConsole and R81.20 GA.&amp;nbsp; Date-related fields such as Release Date, Update Date, and Threat Year are still not searchable.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Apr 2023 16:51:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/Find-status-of-IPS-based-on-CVE-identifiers/m-p/178808#M7633</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-04-22T16:51:03Z</dc:date>
    </item>
  </channel>
</rss>

