Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ross_Wood
Participant

OpenSSH upgrade R81.10

Hi,

 

We have just had a pen test done on our Checkpoint management server which is running R810.10 take 79 and it has stated we have OpenSSH version 7.8 installed and this needs to be upgraded to version 9.1. From the pen test is says the system is running OpenSSH version 7.8p1 which has known flaw that allows Man-in-the-Middle attacks. A successful attack can expose privileged encrypted data.

Does anyone know if OpenSSH can be upgraded on this version of R81.10?

 

Thanks.

0 Kudos
3 Replies
_Val_
Admin
Admin

Please review sk100647 & sk65269. I do not think the results of your penetration tests are valid.

PhoneBoy
Admin
Admin

It is not possible to update the OpenSSH version independently of the version of the Security Gateway.
In R81.20, we also distribute OpenSSH_7.8p1.
Having said that, we also evaluate the various CVEs filed against OpenSSH and patch our versions accordingly, if necessary.
See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

Chris_Atkinson
Employee Employee
Employee

The alphanumeric version code isn't sufficient to determine exposure.

Some related previous discussion is available here:

https://community.checkpoint.com/t5/Security-Gateways/ssh-version-hide-while-telnet-to-gateway-port-... 

CCSM R77/R80/ELITE

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events