Hello,
This is a question regarding the latest Apache CVE`es, more specifically CVE-2021-41773 & CVE-2021-42013
Check Point has released "sk176113" with a hotfix that is supported on most (not all) major versions/platforms on the latest Jumbo.
The sk176113 states that "No CVE in the list below may compromise Check Point products" and the sk has Medium Severity
with little information on which products/functionality that may be vulnerable/exploitable.
Does this actually mean that all Check Point versions from R80.10 are vulnerable and needs to be patched ASAP ?
Would have thought that this would be a "Very Critical" sk with alarms to all partners and customers and not just a "Medium" sk if that was the case ?
Thanks!
Regards.
Petter D
CCSM / CCSE / CCVS / CCTE