<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS signature for CVE-2024-24919 not preventing in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215982#M35816</link>
    <description>&lt;P&gt;Correct, so it is better to install the patch.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 31 May 2024 21:14:35 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2024-05-31T21:14:35Z</dc:date>
    <item>
      <title>IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215977#M35813</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am testing the IPS signature for CVE-2024-24919 and it doesn't seem to be preventing. I am intentionally not installing the hotfix for the CVE to test the IPS signature. It is also not working on gateways with the exploit (I mean it should be detecting the traffic coming in even if the exploit is patched. It would be good to know who is still attempting to exploit it).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-05-31_14-52.png" style="width: 758px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25999i7E5BBC8F134C936C/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-05-31_14-52.png" alt="2024-05-31_14-52.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-05-31_14-53.png" style="width: 711px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26000i0CD5F636B9E26CF2/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-05-31_14-53.png" alt="2024-05-31_14-53.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-05-31_14-55.png" style="width: 759px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26001iF91328B36F42183B/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-05-31_14-55.png" alt="2024-05-31_14-55.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-05-31_15-07.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26006i4C386E9BA4359C84/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-05-31_15-07.png" alt="2024-05-31_15-07.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-05-31_14-57.png" style="width: 597px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26002i2F10CEDCFD1F3127/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-05-31_14-57.png" alt="2024-05-31_14-57.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-05-31_14-59.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26003i97A9C2CB1C9F21F1/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-05-31_14-59.png" alt="2024-05-31_14-59.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-05-31_15-02.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26004i7E7DC68097D64F97/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-05-31_15-02.png" alt="2024-05-31_15-02.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't see a log of the gateway IPS engine logging this attempt and you can clearly see in the screenshot above this one that it did go through.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-05-31_15-03.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26005i50119EECA4DECEED/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-05-31_15-03.png" alt="2024-05-31_15-03.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I think it would be good to have a log of what IPs are trying to exploit this on a gateway even after patching.&lt;/P&gt;&lt;P&gt;I thought it might be a good idea to bring this up with the Check Mate community after testing it in my home lab &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Diyaa&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 21:07:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215977#M35813</guid>
      <dc:creator>Diyaa3791</dc:creator>
      <dc:date>2024-05-31T21:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215979#M35814</link>
      <description>&lt;P&gt;This is due:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To prevent any attempt to exploit this vulnerability, you must protect the vulnerable Remote Access VPN gateway&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;behind&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;a Security Gateway with both IPS and HTTPS Inspection enabled.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Listed in&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182336" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk182336&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 21:13:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215979#M35814</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-05-31T21:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215981#M35815</link>
      <description>&lt;P&gt;So, I actually need another gateway in front of a gateway to actually log and detect this?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 21:13:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215981#M35815</guid>
      <dc:creator>Diyaa3791</dc:creator>
      <dc:date>2024-05-31T21:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215982#M35816</link>
      <description>&lt;P&gt;Correct, so it is better to install the patch.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 21:14:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215982#M35816</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-05-31T21:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215983#M35817</link>
      <description>&lt;P&gt;I am installing the patch. I just thought it would be nice to see the attempts in the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 21:15:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215983#M35817</guid>
      <dc:creator>Diyaa3791</dc:creator>
      <dc:date>2024-05-31T21:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215985#M35818</link>
      <description>&lt;P&gt;What I did is added all the known IP's and ranges to the gateway drop rule and make one group. (listed in SK)&lt;/P&gt;
&lt;P&gt;And then use the group to search in old logs to see if something pops up there. It is not relevant to your questions just a tip.&lt;/P&gt;
&lt;P&gt;Will take couple min to make the objects or script them&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 21:19:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215985#M35818</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-05-31T21:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215986#M35819</link>
      <description>&lt;P&gt;I get what you are saying. Although port TCP/443 is a famous port, and it is always being scanned. The reason it would be nice to have an IPS detect log is to know who is actually still trying to exploit after the patch is on. Those IPs in the SKs would be good to look for in the log, but again. My goal to see all exploitation attempts from any IP with an IPS log.&lt;/P&gt;&lt;P&gt;I don't think this is doable for gateways directly attached to the internet, but that is what I was trying to look for.&lt;/P&gt;&lt;P&gt;With all that being said, I think you gave some nice tips and did amazing trying to assist with this &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;. You deserve a gold star. Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 21:37:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215986#M35819</guid>
      <dc:creator>Diyaa3791</dc:creator>
      <dc:date>2024-05-31T21:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215987#M35820</link>
      <description>&lt;P&gt;You can see the logs by just searching "mycrl" and you'll see all the attempts.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 21:40:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215987#M35820</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-05-31T21:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215989#M35821</link>
      <description>&lt;P&gt;Able to share a screenshot of an example? I could use this information after the weekend. Many thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 21:44:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215989#M35821</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-05-31T21:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215991#M35822</link>
      <description>&lt;P&gt;Sure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26008iED462789CF402904/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 21:49:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215991#M35822</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-05-31T21:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215992#M35823</link>
      <description>&lt;P&gt;Is this a gateway behind another gateway?&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 21:51:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215992#M35823</guid>
      <dc:creator>Diyaa3791</dc:creator>
      <dc:date>2024-05-31T21:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215993#M35824</link>
      <description>&lt;P&gt;Thanks! With https inspection I assume?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 21:58:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215993#M35824</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-05-31T21:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215997#M35825</link>
      <description>&lt;P&gt;Nope, it is the Internet facing gateway.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 23:23:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215997#M35825</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-05-31T23:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215998#M35826</link>
      <description>&lt;P&gt;Correct.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 23:24:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215998#M35826</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-05-31T23:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215999#M35827</link>
      <description>&lt;P&gt;I saw the same in my lab, with https inspection on.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 23:29:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/215999#M35827</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-31T23:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPS signature for CVE-2024-24919 not preventing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/216040#M35847</link>
      <description>&lt;P&gt;This IPS signature only protects gateways BEHIND one it is enforced on.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jun 2024 10:36:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-signature-for-CVE-2024-24919-not-preventing/m-p/216040#M35847</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-06-01T10:36:44Z</dc:date>
    </item>
  </channel>
</rss>

