<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Various Vulnerabilities on secure platform firewall in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Various-Vulnerabilities-on-secure-platform-firewall/m-p/82761#M16732</link>
    <description>&lt;P&gt;Hello guys , this is my first post here so i am hope i will have some help&lt;/P&gt;&lt;P&gt;i received some tasks to fix some vulnerabilities on one of our cluster&amp;nbsp; fw, which is very old secure Platform R75.40... i know its old , end of support etc and there are plans to upgrade/renew it in near future.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i was trying to find something in the google etc, but most articles are related to newer version like 77.30 and 80.x&lt;/P&gt;&lt;P&gt;i will list some of those issues so maybe someone give me a tips how to fix it in this old platform.&lt;/P&gt;&lt;P&gt;1: Disable SSLv3. Services that must support SSLv3 should enable the TLS Fallback SCSV mechanism until SSLv3 can be disabled. and it is related to SSLv3 Padding vuln.&lt;/P&gt;&lt;P&gt;i found some post &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120846" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120846&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but again it is related to newer version so i wonder if there is something similar for my version and platform.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.SSL Medium Strength Cipher Suites Supported CVE-2016-2183&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know how to safely fix that on this platform? and what cipher to use in this case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Contact the vendor or consult product documentation to disable CBC mode cipher encryption, and enable CTR or GCM cipher mode encryption. realated to: CVE-2008-5161&lt;/P&gt;&lt;P&gt;What ciphers i would need to add and where ssh_conf or sshd_conf&amp;nbsp; (in sshd_conf there is no ciphers at all)&lt;/P&gt;&lt;P&gt;also there is need to restart ssh after that , is it risk i will lose connection to the box in case of some mistake?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry for question which can looks trivial&amp;nbsp; but i am new to checkpoint and&amp;nbsp; especially to such old platform so i will be thankful for any help&lt;/P&gt;&lt;P&gt;and if i posted it in wrong location please move it or let me know to avoid it in the future.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Apr 2020 11:28:15 GMT</pubDate>
    <dc:creator>Jaro</dc:creator>
    <dc:date>2020-04-22T11:28:15Z</dc:date>
    <item>
      <title>Various Vulnerabilities on secure platform firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Various-Vulnerabilities-on-secure-platform-firewall/m-p/82761#M16732</link>
      <description>&lt;P&gt;Hello guys , this is my first post here so i am hope i will have some help&lt;/P&gt;&lt;P&gt;i received some tasks to fix some vulnerabilities on one of our cluster&amp;nbsp; fw, which is very old secure Platform R75.40... i know its old , end of support etc and there are plans to upgrade/renew it in near future.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i was trying to find something in the google etc, but most articles are related to newer version like 77.30 and 80.x&lt;/P&gt;&lt;P&gt;i will list some of those issues so maybe someone give me a tips how to fix it in this old platform.&lt;/P&gt;&lt;P&gt;1: Disable SSLv3. Services that must support SSLv3 should enable the TLS Fallback SCSV mechanism until SSLv3 can be disabled. and it is related to SSLv3 Padding vuln.&lt;/P&gt;&lt;P&gt;i found some post &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120846" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120846&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but again it is related to newer version so i wonder if there is something similar for my version and platform.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.SSL Medium Strength Cipher Suites Supported CVE-2016-2183&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know how to safely fix that on this platform? and what cipher to use in this case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Contact the vendor or consult product documentation to disable CBC mode cipher encryption, and enable CTR or GCM cipher mode encryption. realated to: CVE-2008-5161&lt;/P&gt;&lt;P&gt;What ciphers i would need to add and where ssh_conf or sshd_conf&amp;nbsp; (in sshd_conf there is no ciphers at all)&lt;/P&gt;&lt;P&gt;also there is need to restart ssh after that , is it risk i will lose connection to the box in case of some mistake?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry for question which can looks trivial&amp;nbsp; but i am new to checkpoint and&amp;nbsp; especially to such old platform so i will be thankful for any help&lt;/P&gt;&lt;P&gt;and if i posted it in wrong location please move it or let me know to avoid it in the future.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 11:28:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Various-Vulnerabilities-on-secure-platform-firewall/m-p/82761#M16732</guid>
      <dc:creator>Jaro</dc:creator>
      <dc:date>2020-04-22T11:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: Various Vulnerabilities on secure platform firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Various-Vulnerabilities-on-secure-platform-firewall/m-p/83078#M16799</link>
      <description>The time that you spend "fixing" these vulnerabilities would be better spent upgrading to a supported release, given that R75.40 has been End of Support for 4 years now. &lt;BR /&gt;&lt;BR /&gt;In particular, R75.4x only supports TLS 1.0 and has a fairly old version of OpenSSH installed.&lt;BR /&gt;It might require a hotfix to disable SSLv3, e.g. &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102989" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102989&lt;/A&gt;&lt;BR /&gt;If this hotfix doesn't work as-is, you may be out-of-luck as R75.4x is end of support. &lt;BR /&gt;&lt;BR /&gt;I imagine you can follow whatever steps they suggest for OpenSSH, keeping in mind we use an older version.&lt;BR /&gt;This requires a restart of the SSH daemon.&lt;BR /&gt;&lt;BR /&gt;But like I said, you're better off fixing this problem by upgrading to a supported release.</description>
      <pubDate>Fri, 24 Apr 2020 15:17:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Various-Vulnerabilities-on-secure-platform-firewall/m-p/83078#M16799</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-24T15:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Various Vulnerabilities on secure platform firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Various-Vulnerabilities-on-secure-platform-firewall/m-p/83223#M16823</link>
      <description>thank you very much for clarification</description>
      <pubDate>Mon, 27 Apr 2020 05:43:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Various-Vulnerabilities-on-secure-platform-firewall/m-p/83223#M16823</guid>
      <dc:creator>Jaro</dc:creator>
      <dc:date>2020-04-27T05:43:00Z</dc:date>
    </item>
  </channel>
</rss>

