Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dnpl
Participant
Jump to solution

OpenSSL Vulnerability

On Tuesday, November 1, 2022, the OpenSSL project will release a new version of OpenSSL version 3.0.7 that will patch an as-yet-undisclosed vulnerability in current versions of OpenSSL. See following for details:

https://blog.qualys.com/vulnerabilities-threat-research/2022/10/31/qualys-research-alert-prepare-for...

This is likely to impact Check Point Scanners and possibly every linux-based device and third-party software product we have which uses a web portal for management.

Is Checkpoint planning to release a fix for vulnerability?

0 Kudos
3 Solutions

Accepted Solutions
Chris_Atkinson
Employee Employee
Employee

We published a blog that no doubt will be updated as additional information becomes known including relevant IPS signatures & SK articles. 

https://blog.checkpoint.com/2022/10/30/openssl-gives-heads-up-to-critical-vulnerability-disclosure-c...

CCSM R77/R80/ELITE

View solution in original post

Danny
Champion Champion
Champion

@dnpl : Your link writes "Only OpenSSL versions 3.0 through 3.0.6 are vulnerable", so Check Point is not affected.
Simply verify your openssl version with this command:

[Expert@fw:0]# cpopenssl version
OpenSSL 1.1.1n  15 Mar 2022

Confirmed by Check Point in sk92447 and sk180206

View solution in original post

0 Kudos
5 Replies
Chris_Atkinson
Employee Employee
Employee

We published a blog that no doubt will be updated as additional information becomes known including relevant IPS signatures & SK articles. 

https://blog.checkpoint.com/2022/10/30/openssl-gives-heads-up-to-critical-vulnerability-disclosure-c...

CCSM R77/R80/ELITE
Danny
Champion Champion
Champion

@dnpl : Your link writes "Only OpenSSL versions 3.0 through 3.0.6 are vulnerable", so Check Point is not affected.
Simply verify your openssl version with this command:

[Expert@fw:0]# cpopenssl version
OpenSSL 1.1.1n  15 Mar 2022

Confirmed by Check Point in sk92447 and sk180206

0 Kudos
dnpl
Participant

Hi @Danny 

So which version of OpenSSL does checkpoint use?

Thanks

0 Kudos
Danny
Champion Champion
Champion

Version 1.1.1 as shown in my post above and in sk92447.

(1)
_Val_
Admin
Admin
(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events