- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Missing IPS protection?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Missing IPS protection?
We ran a health check (HCP), and it shows the following:
Protections Impact
IPS | Dynamic_Losant Arduino MQTT Client Buffer Overflow (CVE-2018-17614) | M^AGI$C3A | 6.02% |
We would like to inactivate this protection, but it is impossible to find using SmartConsole or GuiDBedit.
Any suggestions?
- Labels:
-
IPS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Let me search it in the lab and report back.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just checked in both R81.20 and R82 and cant find that CVE anywhere, either in IPS or inspection settings. I see some protections for buffer overflow, but nothing with exact same name.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't find the protection on my end, either.
Suggest a TAC case: https://help.checkpoint.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you add a screenshot of the output including the test name?
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Here comes a screenshot.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is a protection that was available in the past. I'm checking if it has been removed and if we need to update HCP tests.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have ran Pattern Matcher statistics according to sk43733, and it shows the same result.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I sent the question to relevant owners in R&D.
It exists on the machine in various locations but perhaps it is not active.
Waiting for the reply from owners.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is it not this but then the other way around? That it got removed instead of added.
https://support.checkpoint.com/results/sk/sk171752
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you heard anything from R&D yet?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
They are currently looking at the issue.
Will update once I know more.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Any news?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
basic check to make sure IPS is ok.
You have valid license (cplic print)?
IPS updated? (ips stat)
Version supported (cpinfo -y all)
If you like this post please give a thumbs up(kudo)! 🙂
