Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Daniel_Kavan
MVP Gold
MVP Gold
Jump to solution

openssh <10.3

Whether Check Point or the community agrees with Nessus or not, this is the first HIGH rating I've seen from nessus on Check Point.  Also, I'm not seeing a fix from Check Point on this one.   https://support.checkpoint.com/results/sk/sk65269   What's everyone else telling their CISO?  We have a policy to fix High rating in so many days.

The OpenSSH < 10.3 Multiple Vulnerabilities plugin is flagged as a "High" severity issue because these older versions contain several severe security flaws—most notably a certificate processing bug and a command injection vulnerability. [1, 2, 3]
These vulnerabilities allow attackers to potentially achieve full root shell access, bypass access controls, or execute unauthorized commands. [1, 2, 3]
  • Authorized Keys Principal Flaw (CVE-2026-35414): A code reuse error allows comma characters in certificate principals to be misinterpreted. If a trusted Certificate Authority (CA) is used, an attacker can exploit this to authenticate as root, completely bypassing access controls. [1, 2]
  • Shell Metacharacters in Usernames (CVE-2026-35386): Command-line username validations were previously performed too late in the connection sequence. An attacker who controls the username can use this flaw to execute arbitrary shell commands on the server. [1, 2]
  • Proxy-Mode Multiplexing Issues (CVE-2026-35388): Connection multiplexing confirmations were omitted in proxy-mode sessions. This creates a weakness that can allow an attacker to establish unauthorized channels. [1]
Because these vulnerabilities directly threaten root-level access and system inte
0 Kudos
2 Solutions

Accepted Solutions
Bob_Zimmerman
MVP Gold
MVP Gold

We discussed that first one, CVE-2026-35414 in an earlier thread. It's very unlikely anybody has set up their firewalls with certificate-based user authentication.

CVE-2026-35386 and CVE-2026-35388 are client-side vulnerabilities. That is, to exploit them, the attacker would need to already have access to run commands on the firewall, at which point they can take advantage of a large number of local privilege escalation flaws in software Check Point ships. It's not great, but it's no worse than the old version of sudo, the old version of vim, the old version of BASH, and so on.

View solution in original post

Bob_Zimmerman
MVP Gold
MVP Gold

CVE-2026-59999 applies only to configurations which explicitly set both PermitTunnel=yes and DisableForwarding=yes, both of which are non-default options. Not relevant unless you have gone out of your way to tweak the /etc/ssh/sshd_config and keep clish from overwriting it.

CVE-2026-60001 allows brute force attempts on passwords. Not great, but as long as you enforce delays after authentication failures at other levels of your stack (like firewall connection rate limiting, or RADIUS/TACACS authentication rate limiting), it's limited to affecting local accounts (notably including the default 'admin' account). Not great, but not catastrophic.

CVE-2026-60002 is a client-side issue. If an attacker is able to run the SSH client on your firewall, you have bigger problems than this bug.

View solution in original post

(1)
4 Replies
Bob_Zimmerman
MVP Gold
MVP Gold

We discussed that first one, CVE-2026-35414 in an earlier thread. It's very unlikely anybody has set up their firewalls with certificate-based user authentication.

CVE-2026-35386 and CVE-2026-35388 are client-side vulnerabilities. That is, to exploit them, the attacker would need to already have access to run commands on the firewall, at which point they can take advantage of a large number of local privilege escalation flaws in software Check Point ships. It's not great, but it's no worse than the old version of sudo, the old version of vim, the old version of BASH, and so on.

PhoneBoy
Admin
Admin

Like @Bob_Zimmerman said, these sound like ssh client-side vulnerabilities.
Which means, to exploit it, you would have to be an authorized user that has expert-level access to the gateway.
Considering expert mode is root access, if that authorized user truly isn't (i.e. an "attacker"), you've got much bigger issues to worry about.

If you want an official answer, of course, contact TAC.

Daniel_Kavan
MVP Gold
MVP Gold

<10.4

Hi Guys,

Have you seen any response from Check Point on these?

CVE-2026-59999
CVE-2026-60001
CVE-2026-60002

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

CVE-2026-59999 applies only to configurations which explicitly set both PermitTunnel=yes and DisableForwarding=yes, both of which are non-default options. Not relevant unless you have gone out of your way to tweak the /etc/ssh/sshd_config and keep clish from overwriting it.

CVE-2026-60001 allows brute force attempts on passwords. Not great, but as long as you enforce delays after authentication failures at other levels of your stack (like firewall connection rate limiting, or RADIUS/TACACS authentication rate limiting), it's limited to affecting local accounts (notably including the default 'admin' account). Not great, but not catastrophic.

CVE-2026-60002 is a client-side issue. If an attacker is able to run the SSH client on your firewall, you have bigger problems than this bug.

(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events