Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dnpl
Participant
Jump to solution

OpenSSL Vulnerability

On Tuesday, November 1, 2022, the OpenSSL project will release a new version of OpenSSL version 3.0.7 that will patch an as-yet-undisclosed vulnerability in current versions of OpenSSL. See following for details:

https://blog.qualys.com/vulnerabilities-threat-research/2022/10/31/qualys-research-alert-prepare-for...

This is likely to impact Check Point Scanners and possibly every linux-based device and third-party software product we have which uses a web portal for management.

Is Checkpoint planning to release a fix for vulnerability?

3 Solutions

Accepted Solutions
Chris_Atkinson
Employee Employee
Employee

We published a blog that no doubt will be updated as additional information becomes known including relevant IPS signatures & SK articles. 

https://blog.checkpoint.com/2022/10/30/openssl-gives-heads-up-to-critical-vulnerability-disclosure-c...

CCSM R77/R80/ELITE

View solution in original post

Danny
Champion Champion
Champion

@dnpl : Your link writes "Only OpenSSL versions 3.0 through 3.0.6 are vulnerable", so Check Point is not affected.
Simply verify your openssl version with this command:

[Expert@fw:0]# cpopenssl version
OpenSSL 1.1.1n  15 Mar 2022

Confirmed by Check Point in sk92447 and sk180206

View solution in original post

5 Replies
Chris_Atkinson
Employee Employee
Employee

We published a blog that no doubt will be updated as additional information becomes known including relevant IPS signatures & SK articles. 

https://blog.checkpoint.com/2022/10/30/openssl-gives-heads-up-to-critical-vulnerability-disclosure-c...

CCSM R77/R80/ELITE
Danny
Champion Champion
Champion

@dnpl : Your link writes "Only OpenSSL versions 3.0 through 3.0.6 are vulnerable", so Check Point is not affected.
Simply verify your openssl version with this command:

[Expert@fw:0]# cpopenssl version
OpenSSL 1.1.1n  15 Mar 2022

Confirmed by Check Point in sk92447 and sk180206

dnpl
Participant

Hi @Danny 

So which version of OpenSSL does checkpoint use?

Thanks

Danny
Champion Champion
Champion

Version 1.1.1 as shown in my post above and in sk92447.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events