Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
HeikoAnkenbrand
Champion Champion
Champion

Feature Request Firewall + WAF (would have been protected against CVE-2024-24919)

Check Point has been selling firewalls for years and WAFs for some years now.
The interesting question for me is why this is not combined.

For example, there was a WAF in front of the GAIA portal (multi-portal) or the MAB portal,
the attack (CVE-2024-24919) could easily have been detected and can be blocked.

Technically, I don't see any difficulties in implementing something like this.

WAF_1_hggfhgfd553245.png

And both technologies are available from Check Point.
And you would be the first firewall manufacturer to protect its products in this way.

➜ CCSM Elite, CCME, CCTE
0 Kudos
4 Replies
_Val_
Admin
Admin

WAF is insufficient here. Full inbound HTTPS Inspection is required, and it is already being reviewed as an option. We are looking into this very seriously. 

0 Kudos
HeikoAnkenbrand
Champion Champion
Champion

@Dorit_Dor 
Is a feature request for the future.

Why can't you build a WAF in front of your web portals on the firewall in R82.x or R8x in the future?
Then attacks like these would be intercepted on the Check Point firewall.

Browser --> (WAF with Https interseption as reverse proxy) --> (Gaia Portal or MAB Portal)
From my point of view, any WAF would sound an alarm when the following string ‘../../../../../’ is used in communication.

➜ CCSM Elite, CCME, CCTE
0 Kudos
Gera_Dorfman
Employee
Employee

Hi Heiko

We are indeed considering additional protective measures to avoid such issues in the future. Integrating  WAF is one of the options.

Thanks

PhoneBoy
Admin
Admin

In a sense, we've provided this already in the form of vpnf.
The new vpnf process (deployed through AutoUpdater or manually) captures and prevents attempts to execute path traversal.
This was deployed as an interim preventative measure until the CVE-2024-24919 fixes are fully installed on customers’ Security Gateways.
More details here: https://support.checkpoint.com/results/sk/sk182376

Despite the presence of vpnf, installing the Hotfix is the best way to stay protected from this vulnerability.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events