Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
elbergfeldt
Participant
Jump to solution

Check Point LivePatch automation question

Hi, 

Trying to build some automation for the recent CVE (sk1000117) and noticed the LivePatch feature (sk185114)

If creating some kind of automation that checks the value of "BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE" From "cpinfo -y cpupdates" 

Will incremented updates (ex if a new release let's say take 32) include the previous CVE patches? 

So if we are monitoring for "BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE" >= 24 we know that we are safe from the CVE 

Or do we have to monitor specifically for "BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE" = 24 (or JHF >= take with fix ofc)

0 Kudos
1 Solution

Accepted Solutions
Lesley
MVP Platinum
MVP Platinum

I would monitor and check the systems with this command:

  • On a Security Gateway / ClusterXL member: cplp list
  • On a Scalable Platform Security Group: g_all cplp list

Then you are for sure if it is active. Note: sometimes it says ready. This means that this system does not use for example IKE daemon (management server). The patch is ready, so if ever the daemon get's enabled the patch is also there and will change from ready to armed. In here you can also see patches that are active that are already solved by a higher jumbo take. Here is an example output of a mgmt:

 

ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpca:cpca* jumbofix livepatch 0/0 2026-09-01 09:06:07 sk185152
cpcert:cpca* armed livepatch 1/1 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert:iked* ready livepatch 0/0 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert:vpnd* ready livepatch 0/0 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* ready livepatch 0/0 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-10 00:28:11 CVE-2026-85102 CVE-2026-85103
cpm:fwm* jumbofix livepatch 0/0 2026-09-01 09:06:07 sk185152 sk185169

-------
Please press "Accept as Solution" if my post solved it 🙂

View solution in original post

3 Replies
Lesley
MVP Platinum
MVP Platinum

I would monitor and check the systems with this command:

  • On a Security Gateway / ClusterXL member: cplp list
  • On a Scalable Platform Security Group: g_all cplp list

Then you are for sure if it is active. Note: sometimes it says ready. This means that this system does not use for example IKE daemon (management server). The patch is ready, so if ever the daemon get's enabled the patch is also there and will change from ready to armed. In here you can also see patches that are active that are already solved by a higher jumbo take. Here is an example output of a mgmt:

 

ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpca:cpca* jumbofix livepatch 0/0 2026-09-01 09:06:07 sk185152
cpcert:cpca* armed livepatch 1/1 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert:iked* ready livepatch 0/0 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert:vpnd* ready livepatch 0/0 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* ready livepatch 0/0 2026-09-10 00:28:12 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-10 00:28:11 CVE-2026-85102 CVE-2026-85103
cpm:fwm* jumbofix livepatch 0/0 2026-09-01 09:06:07 sk185152 sk185169

-------
Please press "Accept as Solution" if my post solved it 🙂
elbergfeldt
Participant

That was a nifty tip, thank you! 

0 Kudos
Duane_Toler
MVP Silver
MVP Silver

If you're using Ansible, I just published my latest version of a module collection for Check Point facts-gathering to inventory the live patch status across your fleet:

https://community.checkpoint.com/t5/Automation-and-APIs/Ansible-module-collection-for-Check-Point-ho...

The collection is available now on Ansible Galaxy.

This is just facts-gathering only; not deployment of the live patch packages.

 

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events