<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Are Check Point appliances vulnerable to Red-Hat CVE-2021-435? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Are-Check-Point-appliances-vulnerable-to-Red-Hat-CVE-2021-435/m-p/135727#M24276</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Pretty much what the subject says, RH have identified a critical vulnerability (&lt;SPAN&gt;remote code execution flaw)&lt;/SPAN&gt; in NSS as per&amp;nbsp;&lt;A href="https://access.redhat.com/security/cve/CVE-2021-43527" target="_self"&gt;https://access.redhat.com/security/cve/CVE-2021-43527&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If I understand the R81 hardening guide correctly, &lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_Hardening/Topics-GAH/Unchanged_RPM_Packages_from_RHEL_7_8.htm?tocpath=_____7" target="_self"&gt;it lists NSS as one of the RPM's that's unchanged in Gaia&lt;/A&gt;.&amp;nbsp; Is this something that needs to be patched by Check Point?&lt;/P&gt;
&lt;P&gt;I did log a ticket with TAC, but thought I would ask / share here as well while I wait for an official answer from them.&lt;/P&gt;
&lt;P&gt;Ruan&lt;/P&gt;</description>
    <pubDate>Tue, 07 Dec 2021 12:02:16 GMT</pubDate>
    <dc:creator>Ruan_Kotze</dc:creator>
    <dc:date>2021-12-07T12:02:16Z</dc:date>
    <item>
      <title>Are Check Point appliances vulnerable to Red-Hat CVE-2021-435?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-Check-Point-appliances-vulnerable-to-Red-Hat-CVE-2021-435/m-p/135727#M24276</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Pretty much what the subject says, RH have identified a critical vulnerability (&lt;SPAN&gt;remote code execution flaw)&lt;/SPAN&gt; in NSS as per&amp;nbsp;&lt;A href="https://access.redhat.com/security/cve/CVE-2021-43527" target="_self"&gt;https://access.redhat.com/security/cve/CVE-2021-43527&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If I understand the R81 hardening guide correctly, &lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_Hardening/Topics-GAH/Unchanged_RPM_Packages_from_RHEL_7_8.htm?tocpath=_____7" target="_self"&gt;it lists NSS as one of the RPM's that's unchanged in Gaia&lt;/A&gt;.&amp;nbsp; Is this something that needs to be patched by Check Point?&lt;/P&gt;
&lt;P&gt;I did log a ticket with TAC, but thought I would ask / share here as well while I wait for an official answer from them.&lt;/P&gt;
&lt;P&gt;Ruan&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 12:02:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-Check-Point-appliances-vulnerable-to-Red-Hat-CVE-2021-435/m-p/135727#M24276</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2021-12-07T12:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Are Check Point appliances vulnerable to Red-Hat CVE-2021-435?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-Check-Point-appliances-vulnerable-to-Red-Hat-CVE-2021-435/m-p/135732#M24277</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9028"&gt;@Ruan_Kotze&lt;/a&gt;,&amp;nbsp;R&amp;amp;D is looking into this. The official response will be provided shortly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 13:36:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-Check-Point-appliances-vulnerable-to-Red-Hat-CVE-2021-435/m-p/135732#M24277</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-12-07T13:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Are Check Point appliances vulnerable to Red-Hat CVE-2021-435?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Are-Check-Point-appliances-vulnerable-to-Red-Hat-CVE-2021-435/m-p/135885#M24300</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9028"&gt;@Ruan_Kotze&lt;/a&gt;&amp;nbsp;and all. Here is the official response:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We have carefully reviewed the situation, and found that while the vulnerable NSS package exists on Gaia, there is no direct use of it in any of our products. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Therefore, &lt;U&gt;Check Point Gaia is not vulnerable to CVE-2021-43527&lt;/U&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Having said that, we are working on upgrading the NSS package to a version that isn’t vulnerable.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Dec 2021 07:39:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Are-Check-Point-appliances-vulnerable-to-Red-Hat-CVE-2021-435/m-p/135885#M24300</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-12-09T07:39:29Z</dc:date>
    </item>
  </channel>
</rss>

