Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Eran_Habad
Employee
Employee

Hardening Recommendation Report Now Includes CVE Exposure Visibility

Hi all,
 

Recently, we launched the Hardening Recommendation Report in Web SmartConsole, enabling administrators to review and improve the security posture of their Security Gateways and Management Servers.

Today, we're extending the Hardening Recommendation Report with CVE Exposure visibility, helping security teams quickly identify vulnerable devices, prioritize remediation efforts, and better understand their overall risk exposure.

The report now highlights known Check Point CVEs affecting Security Gateways and Management Servers, indicates whether each applicable CVE is patched, and provides actionable remediation information for devices that still require attention.

An illustrated example:

Image (11).png

The report summary includes:

  • Unpatched CVEs – The number of known CVEs that remain unpatched and the number of affected devices.
  • Highest CVSS Exposure – The highest CVSS score among all unpatched CVEs detected in the environment.

Also, for each device, the report provides detailed vulnerability information, including any unpatched Check Point CVEs and the corresponding remediation path. When a CVE is resolved in a later Jumbo Hotfix, the report displays the required JHF take that contains the fix. When a CVE is addressed through Check Point Live Patch, the report provides the patch installation status. If the patch was successfully installed, the CVE in the device is marked as patched. If the patch installation failed, the report displays the reason for the failure to help administrators take the necessary corrective actions.

With CVE Exposure integrated directly into the Hardening Recommendation Report, security teams can more easily assess their exposure, prioritize remediation efforts, and ensure critical security updates are applied across their environment 🚀

As always, we'd love to hear your feedback and suggestions for future improvements.

Eran

(1)
29 Replies
JozkoMrkvicka
Authority
Authority

Is the Hardening Recommendation Report visible ONLY in WSC (Web SmartConsole) ? Or also on installed SC ?

Kind regards,
Jozko Mrkvicka
0 Kudos
Lesley
MVP Platinum
MVP Platinum

Only Webconsole. Not installed SmartConsole

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
CaseyB
Advisor

Awesome!

Looks like there is a discrepancy between a Cluster Object and Cluster Members though.

cve-cluster.pngcve-member.png

Lesley
MVP Platinum
MVP Platinum

I had the same, this needs to be tweaked, it shows different stuff, that might cause people to get confused. 

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
EVeloso
Explorer

Same situation here.
In the cluster, the status is "unpatched - install jumbo hotfix", but in each member, it says there is no CVE exposure.

0 Kudos
Lesley
MVP Platinum
MVP Platinum

Are spark firewalls supported? They seem to be included but I see data some data is not correct. R82.0.10 spark firmware. 

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
CaseyB
Advisor

I was wondering the same on the spark appliances. Our 1535 devices are fully patched, and the CVE list is looking rough.

 

1535-cve.png

0 Kudos
Eran_Habad
Employee
Employee

Thanks for the feedback @CaseyB and @Lesley. I'll reach out directly to each of you to review this.

0 Kudos
Eran_Habad
Employee
Employee

Thanks again for the feedback @CaseyB and @Lesley.

I acknowledge that the current results for the Cluster Gateway itself and for Spark Gateways are not accurate and can be disregarded. It is important to note, however, that for cluster Gateways, the results reported for the individual cluster members are accurate and provide the full information you need.

We have already identified the issue and a fix is scheduled to be released early next week. The update will be deployed automatically for customers with automatic updates enabled.

0 Kudos
D_TK
Advisor

Is this available in the fat client SC?  We only use p12 certs for SC logon so web con is not available to us.

0 Kudos
Eran_Habad
Employee
Employee

Hi, as stated above it's not available through SmartConsole, only through Web SmartConsole. However, we'll check the option to retrieve the file manually and directly from the Management Server itself (it will require SSH/SCP access to the Management though).

0 Kudos
ccsjnw
Advisor

Please add the ability to access this from within SmartConsole. That’s where Administrator’s live day-to-day. The vast majority of customers *never* use Web Smart Console..

0 Kudos
Eran_Habad
Employee
Employee

Hi,

Soon this information will also be available in SmartConsole, as part of the Gateways and Servers tab. This is an illustration:

Screenshot 2026-09-25 115044.png

At the moment, we don't plan to have the entire Hardening Report in SmartConsole, only the CVE Exposure.

Eran

0 Kudos
ccsjnw
Advisor


If it's not available in SmartConsole, can we automate it so that the Security Report is sent weekly to an email distribution list, like we do with custom SmartView reports? We need a way that administrators can get the report without manually logging into Web Smart Console - because they just won't.

0 Kudos
basinUnaltered
Contributor

This is a great feature! What is the minimum version for this? I'm running R81.20 on management server with Web SmartConsole version 179 but my hardening reports do not appear to include CVE Exposure.

0 Kudos
shovalm
Employee
Employee

Hi @basinUnaltered 
These are the minimum required versions, as specified in https://support.checkpoint.com/results/sk/sk185102  : 

min_versions.png

feel free to reach me directly if you encounter any issue. 

0 Kudos
michael_edwards
Explorer

Neat, I like the format. 

We have a few devices (R82 & mix of Takes) showing 'Unpatched - Install Jumbo Hotfix' even when it is live patched. Is this normal? It has meant I have had to check each of them to confirm that the live patch was active. 

0 Kudos
HienTM
Participant

Thank you. We love this report, very neat and informative.

We have small problem with report accuracy. On our management server Smart-1 600S running 81.20 we applied JHF take 166 on 21-Sep-2026 but today 23-Sep-2026 the report still shows that CVE-2026-18574 still not patched and the fix for the patch is in Take 161. Is there any way to force the report to update the latest information/refresh?

The last report refresh was 2026-09-22 23:30

hrr_260923.jpg

although Take 166 was applied 2 days ago

cpinfo_260923.jpg

Thank you.

Hien

0 Kudos
Amiad_Stern
Employee
Employee

Hi @HienTM ,
Thanks for your feedback.

You can re-run ("refresh") by executing this command:

cd $MDS_FWDIR/log/cpm_doctor && $MDS_FWDIR/scripts/run_cpmdoc.sh -s

If things are still the same, I would like to keep investigating your issue offline.

Can you please send me ([email protected]) the following:

  • Output of the following command to check the pkg installed: autoupdatercli show
  • Files (for offline debug):
    • $MDS_FWDIR/log/cpm_doctor/hardening/*.*
    • $MDS_FWDIR/log/cpm_doctor/cpm_doctor_report<date and time>.tar.gz

We will continue our correspondence by mail after you will send me the files.

Regards,
Amiad

0 Kudos
HienTM
Participant

Dear Amiad,

Thank you for your reply. The information requested was sent.

Best Regards,

Hien

0 Kudos
Hugo_vd_Kooij
MVP Gold
MVP Gold

Found another issue. R82 Jumbo Hotfix Take 127 is installed. But I am still vulnerable to issue fixed in Jumbo Hotfix Take 126.

So at the moment it means we can't rely on this.

<< We make miracles happen while you wait. The impossible jobs take just a wee bit longer. >>
0 Kudos
Amiad_Stern
Employee
Employee

@Hugo_vd_Kooij , thanks for your feedback.

In the image you shared I can't see if it is the Management Server. If yes, we discovered this issue yesterday and we are working on it. 

Regards,

Amiad.

0 Kudos
Hugo_vd_Kooij
MVP Gold
MVP Gold

It's management.

<< We make miracles happen while you wait. The impossible jobs take just a wee bit longer. >>
Oliver_Fink
Advisor
Advisor

Very nice tool. Is there any possibility or plan, that this report can be created automatically in a parseable format (JSON, …) or in Markdown? Management API or script?

Alex-
MVP Silver
MVP Silver

Some of our customers asked exactly this. I understand the feature is still new, it would make sense to add it to the Management API suite in an upcoming update.

0 Kudos
Eran_Habad
Employee
Employee

Yes, it's on the roadmap.

David_C1
Advisor

With my on-prem SMS servers (we have lab and prod environments), I am net getting the CVE information in the hardening reports. We are running R82 with JHFA Take 122 in prod, R82 with JHFA Take 127 in lab, Web SmartConsole version 179 in both. "Standard" tests return data:

lab1.jpg

CVE tests do not show any data:

lab3.jpg

0 Kudos
Amiad_Stern
Employee
Employee

@David_C1 , we are examining similar case, I will contact you offline.

0 Kudos
Network_Engine1
Explorer

Do you allow your SMS/MDS internet access to checkpoint ?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events