Recently, we launched the Hardening Recommendation Report in Web SmartConsole, enabling administrators to review and improve the security posture of their Security Gateways and Management Servers.
Today, we're extending the Hardening Recommendation Report with CVE Exposure visibility, helping security teams quickly identify vulnerable devices, prioritize remediation efforts, and better understand their overall risk exposure.
The report now highlights known Check Point CVEs affecting Security Gateways and Management Servers, indicates whether each applicable CVE is patched, and provides actionable remediation information for devices that still require attention.
An illustrated example:
The report summary includes:
- Unpatched CVEs – The number of known CVEs that remain unpatched and the number of affected devices.
- Highest CVSS Exposure – The highest CVSS score among all unpatched CVEs detected in the environment.
Also, for each device, the report provides detailed vulnerability information, including any unpatched Check Point CVEs and the corresponding remediation path. When a CVE is resolved in a later Jumbo Hotfix, the report displays the required JHF take that contains the fix. When a CVE is addressed through Check Point Live Patch, the report provides the patch installation status. If the patch was successfully installed, the CVE in the device is marked as patched. If the patch installation failed, the report displays the reason for the failure to help administrators take the necessary corrective actions.
With CVE Exposure integrated directly into the Hardening Recommendation Report, security teams can more easily assess their exposure, prioritize remediation efforts, and ensure critical security updates are applied across their environment 🚀
- For more information about the Hardening Report and the new CVE Exposure capabilities, refer to: sk185102 - Hardening Recommendation Report
- For more information about Check Point Live Patch, refer to: sk185114 - Check Point Live Patch (CPLP)
As always, we'd love to hear your feedback and suggestions for future improvements.
Eran



