Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
tavi0906
Contributor
Jump to solution

Vulnerability CVE-2024-7264

 

There are VA detected on checkpoint smart console as following. Kindly advise how to fix.

 

 

as a trail solution i  have installed the latest build for smartconsole and the issue is still same

 

 

Medium

205024

CVE-2024-7264

libcurl 7.32.0 < 8.9.1 DoS (CVE-2024-7264)

Upgrade Curl to version 8.9.1 or later


  Path              : C:\Program Files (x86)\CheckPoint\SmartConsole\R81.20\81.20.9700.656\libcurl.dll
  Installed version : 7.61.1.0
  Fixed version     : 8.9.1

0 Kudos
1 Solution

Accepted Solutions
the_rock
MVP Gold
MVP Gold

Check Point firewalls are not vulnerable to CVE-2024-7264 because the vulnerability affects the libcurl library and Check Point products do not use this library.

Best,
Andy

View solution in original post

0 Kudos
15 Replies
the_rock
MVP Gold
MVP Gold

Check Point firewalls are not vulnerable to CVE-2024-7264 because the vulnerability affects the libcurl library and Check Point products do not use this library.

Best,
Andy
0 Kudos
tavi0906
Contributor

is this not correct ?

 

 

0 Kudos
tavi0906
Contributor

In Check Point environments, the main reference to libcurl is through the command-line utility curl_cli ?

is this not correct ?

0 Kudos
the_rock
MVP Gold
MVP Gold

I think so, yes.

Best,
Andy
0 Kudos
tavi0906
Contributor

Okay. Can we say that Check Point is not vulnerable to this CVE, or has Check Point not yet released any official information regarding it?

0 Kudos
the_rock
MVP Gold
MVP Gold

I even had TAC case about it before and they told me exact same thing, which is that CP firewalls are not vulnerable to mentioned CVE.

Best,
Andy
0 Kudos
tavi0906
Contributor

Oh, would you be able to share a screenshot, please?

0 Kudos
the_rock
MVP Gold
MVP Gold

This was few months ago, will see if I can find an email about it.

Best,
Andy
0 Kudos
tavi0906
Contributor

lib.jpg

0 Kudos
the_rock
MVP Gold
MVP Gold

Thats just smart console folder.

Best,
Andy
0 Kudos
Ruan_Kotze
MVP Gold
MVP Gold

Hey Andy,

You might have missed it but OP was not reporting a libcurl vulnerability on the gateway side, it's reported as being in SmartConsole.

-Ruan

 

the_rock
MVP Gold
MVP Gold

I saw that, yes. Anyway, let Chris confirm internally, to be 100% sure.

Best,
Andy
0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

This was investigated at the time and the vulnerable flow is not in use in our implementation.

Where required requests to upgrade the libcurl version can be made via your SE under the RFE process.

 

CCSM R77/R80/ELITE
the_rock
MVP Gold
MVP Gold

Thats more less what TAC advised as well.

Best,
Andy
0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Whilst I dislike any detection based solely on version I have asked internally about this.

Suggest raising a specific TAC case and looping in your SE aswell.

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events