<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800 in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144334#M6614</link>
    <description>&lt;P&gt;Hi Guys&lt;/P&gt;
&lt;P&gt;we didn't see any bug in APPI. in fact there was no change in this region, so I'll be surprise if there is a bug.&lt;/P&gt;
&lt;P&gt;As for why OpenSSL in not 1.1.1n. the issue was fixed within the same OpenSSL version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Mar 2022 16:58:21 GMT</pubDate>
    <dc:creator>Amir_Ayalon</dc:creator>
    <dc:date>2022-03-21T16:58:21Z</dc:date>
    <item>
      <title>SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144151#M6604</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Upgrade OpenSSL to fix CVE-2022-0778 Refer to &lt;/SPAN&gt;&lt;A href="https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk178411" target="_blank" rel="noopener noreferrer"&gt;sk178411 - Check Point response to OpenSSL CVE-2022-0778.&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2022 11:57:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144151#M6604</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-18T11:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144203#M6606</link>
      <description>&lt;P&gt;I would suggest to not install this fix -&amp;nbsp;i found a serious bug in APPI updates making APCL work no more...&lt;/P&gt;
&lt;P&gt;--&amp;gt; as stated this is not an issue of this firmware, only mine&amp;nbsp;8)&lt;/img&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 18:49:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144203#M6606</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-21T18:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144209#M6607</link>
      <description>&lt;H5&gt;&lt;STRONG&gt;&lt;CODE&gt;pt bladeUpdateStatus&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;H5&gt;3 (2002) =&lt;BR /&gt;modified = nil&lt;BR /&gt;lastSuccessfulCheckTime = 1647770804&lt;BR /&gt;installedUpdateVersion = 0&lt;BR /&gt;availableUpdateVersion = 22030801&lt;BR /&gt;isOfflineUpdate = false&lt;BR /&gt;lastInstallStartedAt = 1647770803&lt;BR /&gt;installStatus = BLADE_INSTALL_STATUS.CONNECTING&lt;BR /&gt;id = 2002&lt;BR /&gt;lastInstallResult = BLADE_INSTALL_RESULT.INSTALL_ERROR&lt;BR /&gt;bladeCode = BLADE.APPLICATION_CONTROL&lt;BR /&gt;lastSuccessfulInstallTime = nil&lt;BR /&gt;upToDateConfirmedAt = nil&lt;/H5&gt;</description>
      <pubDate>Sun, 20 Mar 2022 10:38:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144209#M6607</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-20T10:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144263#M6608</link>
      <description>&lt;P&gt;That seems not to be the only issue here - in GAiA a&lt;SPAN&gt;fter patching, R81.10 and R80.40 show:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;# cpopenssl version&lt;BR /&gt;OpenSSL 1.1.1n 15 Mar 2022&lt;/P&gt;
&lt;P&gt;This is the fixed OpenSSL version !&lt;/P&gt;
&lt;P&gt;But 1550 R80.20.35_992002639:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;# cpopenssl version&lt;BR /&gt;OpenSSL 1.0.2r 26 Feb 2019&lt;/P&gt;
&lt;P&gt;This is the same version as in R80.20.35_992002613. That should be fixed OpenSSL version 1.0.2zd according to&amp;nbsp;&lt;A href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0778" target="_blank" rel="noopener"&gt;CVE-2022-0778&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;So does this firmware fix the issue at all ?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 09:38:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144263#M6608</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-21T09:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144271#M6609</link>
      <description>&lt;P&gt;I have reverted back to&amp;nbsp;&lt;SPAN&gt; R80.20.35_992002613, but Update &amp;amp; APPI is still not working &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 10:12:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144271#M6609</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-21T10:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144276#M6610</link>
      <description>&lt;P&gt;&lt;div class="lia-vid-container video-embed-center"&gt;&lt;div id="lia-vid-6301353097001w604h540r674" class="lia-video-brightcove-player-container"&gt;&lt;video-js data-video-id="6301353097001" data-account="6058022097001" data-player="default" data-embed="default" class="vjs-fluid" controls="" data-application-id="" style="width: 100%; height: 100%;"&gt;&lt;/video-js&gt;&lt;/div&gt;&lt;script src="https://players.brightcove.net/6058022097001/default_default/index.min.js"&gt;&lt;/script&gt;&lt;script&gt;(function() {  var wrapper = document.getElementById('lia-vid-6301353097001w604h540r674');  var videoEl = wrapper ? wrapper.querySelector('video-js') : null;  if (videoEl) {     if (window.videojs) {       window.videojs(videoEl).ready(function() {         this.on('loadedmetadata', function() {           this.el().querySelectorAll('.vjs-load-progress div[data-start]').forEach(function(bar) {             bar.setAttribute('role', 'presentation');             bar.setAttribute('aria-hidden', 'true');           });         });       });     }  }})();&lt;/script&gt;&lt;a class="video-embed-link" href="https://community.checkpoint.com/t5/video/gallerypage/video-id/6301353097001"&gt;(view in My Videos)&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;APCL update status is not displayed, but on clicking the Apply button, APCL tries to update, that is to reach the server, but fails - update is never started !&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 10:51:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144276#M6610</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-21T10:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144277#M6611</link>
      <description>&lt;P&gt;Did you open a TAC case yet?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 10:49:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144277#M6611</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-03-21T10:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144278#M6612</link>
      <description>&lt;P&gt;I just gave feedback to the SK - my wife is watching TV so i can do no debugs&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 10:53:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144278#M6612</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-21T10:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144280#M6613</link>
      <description>&lt;P&gt;never heard that excuse before, lol&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 11:05:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144280#M6613</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-03-21T11:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144334#M6614</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;
&lt;P&gt;we didn't see any bug in APPI. in fact there was no change in this region, so I'll be surprise if there is a bug.&lt;/P&gt;
&lt;P&gt;As for why OpenSSL in not 1.1.1n. the issue was fixed within the same OpenSSL version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 16:58:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144334#M6614</guid>
      <dc:creator>Amir_Ayalon</dc:creator>
      <dc:date>2022-03-21T16:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144344#M6615</link>
      <description>&lt;P&gt;I think that my APPI issue has nothing to do with the firmware version -&amp;nbsp;&lt;SPAN&gt;OpenSSL 1.0.2r 26 Feb 2019 is a fixed version ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 18:48:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144344#M6615</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-21T18:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144345#M6616</link>
      <description>&lt;P&gt;YES - according to R&amp;amp;D the solution is:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The "# cpopenssl version" command applies to R80.40 and above. In R80.30 versions (and below), we do not upgrade the openSSL version but manually port the fix for the CVE. Although there is no easy way to make sure that openSSL was upgraded on these versions, it will be after you install the Hotfix.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 18:51:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144345#M6616</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-21T18:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: SMB OpenSSL Fixes for CVE-2022-0778 are ready for 1500 1600 1800</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144391#M6622</link>
      <description>&lt;P&gt;I have resolved the issue&amp;nbsp;8)&lt;/img&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 09:06:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-OpenSSL-Fixes-for-CVE-2022-0778-are-ready-for-1500-1600-1800/m-p/144391#M6622</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-22T09:06:25Z</dc:date>
    </item>
  </channel>
</rss>

