Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Joe_Kanaszka
Advisor

Question regarding traffic handling?

R81.20

This is concerning CVE-2024-24919.  

We applied the hotfix last year for this and all the recommended other steps.

We use a third party XDR system, and while going through the events from today, I noticed that it says that my Check Point "did not block" traffic related to CVE-2024-24919.

 

When I look at my Check Point logs in Smart Log, I can only see two entries at the same exact time:.  One is my firewall blade telling me it let this traffic through.

The other entry is telling me my IPS rule for CVE-2024-24919 prevented it.

 

I'm guessing this traffic was blocked by my IPS, but why would this pacet not be "dropped"  at the gateway, or is this just a GUI quirk Check Point?

 

Thank you!

 

 

2 Replies
the_rock
Legend
Legend

Do you see the CVE in the logs?

Andy

0 Kudos
PhoneBoy
Admin
Admin

Please make sure ALL of your Check Point gateways are properly patched/upgraded to fix CVE-2024-24919, not just using the IPS signature for it: https://support.checkpoint.com/results/sk/sk182336 

In any case, an Access Policy "accept" followed by a Threat Prevention "drop" is normal since we process Access Policy rules before Threat Prevention.
Which means the traffic should have been dropped by IPS.

What evidence does the XDR provide that the relevant traffic wasn't blocked?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events