Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
HeikoAnkenbrand
Champion Champion
Champion

Patch Installation Example (CVE-2024-24919)

To solve the CVE-2024-24919 issue  sk182336, the following must be done on the Check Point Gateway.

1) First create a snapshot of the gateway
    FIX_5_gdfgdfgfdg.png

2) Open the GAIA PORTAL and check if the latest jumbo hotfix is installed.

     FIX_3_gdfgdfgfdg.png

  3) For R81.20 this would currently be Take 53. If this is not installed, install it. If this Take is already installed, you can skip the step.
     a) Download this Take
     b) Verify the Take
     c) Install this Take

    FIX_6_gdfgdfgfdg.png

4) Reboot the Security Gateway

CVE-2024-24919 on top hotfixes are currently available for the following gateway versions sk182336.

     FIX_9_gdfgdfgfdg.png

5) Afterwards install the special hotfix for the corresponding Jumbo Hotfix version and GAIA version.
     a) Download this hotfix
     b) Verify this hotfix
     c) Install this hotfix
    FIX_7_gdfgdfgfdg.png


6) If you want to prevent users from logging in with their password, you should also install this patch.
    This disables the VPN login for password-only users.
     a) Download this "Security hardening for Remote Access user" patch
     b) Verify this patch
     c) Install this patch


FIX_10_gdfgdfgfdg.png

PS:
The same steps are also possible via SmartConsole.

 

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips
(2)
3 Replies
mylly
Explorer

0 Kudos
OTWal
Explorer

👍

0 Kudos
_Val_
Admin
Admin

Heiko, thanks for the effort, but we do have official recommendations for this CVE in the main announcement post already.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events