3. and 5. -> may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway.
So if you want to be sure, yes reinstall. I think you cannot be 100% sure if they run a code yes or no.
But in the end, recently there are many CVE's for a lot of vendors, it is not manageable to every time clean install the system and change all the passwords, certificates etc. Of course if the CVE states access was possible to the exposed system
I would ask TAC to advise what to do if they indeed abused this CVE. Just assume they have been able to run all the code they wanted, what would TAC advise be?
If you want to make sure the changes are quite a lot think like:
Change all PSK for all tunnels.
Renew all certificates
Change passwords, SNMP ssh access , GRUB, expert etc.
Rotate ICA, renew VPN cert, platform portal,SSL decryp cert etc.
Check out AD servers, the logs, reset service accounts. Maybe check out the service accounts that the check point uses
-------
Please press "Accept as Solution" if my post solved it 🙂