- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello mates,
The current version of OpenSSH and OpenSSL on R81.20 is OpenSSH 7.8p1 and OpenSSL 1.1.1w. According to the Vulnerability Assessment reports, these versions are flagged as having vulnerabilities. What are the latest compatible versions ?
These components should be patched against the relevant CVEs.
See the following SKs:
These components should be patched against the relevant CVEs.
See the following SKs:
We are running R82 with JHFA10 and when we ran a scan against this, was surprised it picked up OpenSSH CVE's from 2018, and 2019 (They are listed in SK65269).
I raised a TAC case and was told this is not a TAC issue. Well CVE's from 2018/2019 on the latest build..hmm I don't think there is an excuse as to why OpenSSH has not been updated to resolve these issues, any chance we can get an update as to when OpenSSH is going to be updated to non-vulnerable version?
That's more an issue with vulnerability scanners being terrible wastes of money. 😜 I keep getting scan results saying systems are vulnerable to CVE-2023-48795, which is categorically not a vulnerability on versions of OpenSSH before 9.5. They basically look at the version in the service banner, ignore it, and report every CVE which has ever existed for the application, no matter whether it represents an actual vulnerability in that environment or not.
I agree - pen test reports never seem to actually indicate what was required in order to actually get to the point they could scan the device.
So it could be a critical vulnerability but the probability of exploit is low due to the layer of security that had to be bypassed in order to reach that point.
That said my comments are coming from the fact the SK from Checkpoint indicates the issue has not been fixed because they believe its a low priority (since 2019!).
If you look at the CVSS scores for the CVEs, they rate between 3.1 and 5.3 (out of 10).
At best they are "low to medium" severity CVEs that require a privileged user on the platform to access a malicious SCP server to be exploited.
This is likely why we have made the determination this is relatively low risk.
I assume we will fix this once the underlying component is updated to a different version, which most likely won't happen outside of a new release.
Thanks.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 14 | |
| 9 | |
| 7 | |
| 7 | |
| 7 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 |
Thu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 10:00 AM (CEST)
Schutz souveräner Workloads: Check Point & die AWS European Sovereign CloudThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY