<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No information about new vulnerability in IPS blade. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184802#M30790</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I checked my CVE on that page, and it doesn't appear in "LIST" either.&lt;/P&gt;
&lt;P&gt;It is recommended to work with the SE, isn't it?&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jun 2023 13:48:21 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2023-06-26T13:48:21Z</dc:date>
    <item>
      <title>No information about new vulnerability in IPS blade.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184727#M30773</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a Firewall Cluster, version R81.10.&lt;BR /&gt;Currently the Cluster has the IPS blade active.&lt;/P&gt;
&lt;P&gt;Our Cybersecurity area has made the detection of a new signature, which require to know if this signature "impacts" or not to any asset of our company.&lt;/P&gt;
&lt;P&gt;I have reviewed in the IPS Protections option from the SmartConsole, the signature that was reported to me, which is:&lt;/P&gt;
&lt;P&gt;Vulnerability in Check Point (CVE-2023-34460) (CVSS Score v3: Undefined).&lt;/P&gt;
&lt;P&gt;But you will notice in the attached image, that apparently, Checkpoint, does not have it included in its database, or I'm checking wrong????&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IPS2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21523iE768DCC21FCC3A54/image-size/large?v=v2&amp;amp;px=999" role="button" title="IPS2.jpg" alt="IPS2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;What kind of action can be taken in this case?&lt;BR /&gt;Currently I have the following version of IPS signatures installed in my Cluster Firewalls.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IPS3.jpg" style="width: 848px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21525i69DDAD85BCA83325/image-size/large?v=v2&amp;amp;px=999" role="button" title="IPS3.jpg" alt="IPS3.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Just to clarify the doubt, the signatures that I find with the "PREVENT" action in Checkpoint's database, does it mean that Checkpoint "blocks" this type of traffic?&lt;/P&gt;
&lt;P&gt;Prevent, is it related to the action of BLOCKING all traffic? Or is it not always like that?&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jun 2023 22:45:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184727#M30773</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-25T22:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: No information about new vulnerability in IPS blade.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184729#M30774</link>
      <description>&lt;P&gt;Generally only when POC code is available can a protection be created.&lt;/P&gt;
&lt;P&gt;If this is critical for you please work with your local CP SE to track it.&lt;/P&gt;
&lt;P&gt;'Prevent' does what it says but there can be some dependencies depending on the type of threat/traffic e.g. HTTPS inspection&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jun 2023 23:39:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184729#M30774</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-06-25T23:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: No information about new vulnerability in IPS blade.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184784#M30787</link>
      <description>&lt;P&gt;You need to update your SmartConsole software.&amp;nbsp; In some early releases you were not allowed to search by CVE number, however this was fixed in later releases.&amp;nbsp; From my &lt;A href="http://www.maxpowerfirewalls.com/ips-av-abot-immersion-r81.20.html" target="_self"&gt;IPS/AV/ABOT Immersion Course&lt;/A&gt;&amp;nbsp;(which was just updated for R81.20) discussing the searching of IPS Protections:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ips_search.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21530i1087ADA55F452EC0/image-size/large?v=v2&amp;amp;px=999" role="button" title="ips_search.png" alt="ips_search.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 12:30:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184784#M30787</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-06-26T12:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: No information about new vulnerability in IPS blade.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184786#M30788</link>
      <description>&lt;P&gt;Alternately you can also search your CVE here: &lt;A href="https://advisories.checkpoint.com/advisories/" target="_blank"&gt;https://advisories.checkpoint.com/advisories/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 12:36:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184786#M30788</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-06-26T12:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: No information about new vulnerability in IPS blade.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184802#M30790</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I checked my CVE on that page, and it doesn't appear in "LIST" either.&lt;/P&gt;
&lt;P&gt;It is recommended to work with the SE, isn't it?&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 13:48:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184802#M30790</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-26T13:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: No information about new vulnerability in IPS blade.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184803#M30791</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Is it possible to "work" with the SmartConsole R81.20, to access my SMS which is in version R81.10?&lt;/P&gt;
&lt;P&gt;Or am I forced to update the SMS Gaia to R81.20?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 13:50:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184803#M30791</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-26T13:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: No information about new vulnerability in IPS blade.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184804#M30792</link>
      <description>&lt;P&gt;The SE can make a request internally, again depending on POC code availability.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 13:51:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184804#M30792</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-06-26T13:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: No information about new vulnerability in IPS blade.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184845#M30797</link>
      <description>&lt;P&gt;&lt;SPAN&gt;A cursory read of CVE-2023-34460 suggests the issue is in a piece of software used to build other software.&lt;BR /&gt;&lt;/SPAN&gt;I fail to see how any network-based IPS would protect against this vulnerability.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 18:54:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/No-information-about-new-vulnerability-in-IPS-blade/m-p/184845#M30797</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-26T18:54:40Z</dc:date>
    </item>
  </channel>
</rss>

