- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Signature for CVE-2020-1968
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Signature for CVE-2020-1968
Hello
Is it possible to have a signature for CVE-2020-1968 in Check Point IPS?
I think it cannot because Check Point cannot inspect a key between a connection.
If you have more information, please recommend me.
Thank you.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you sure you need it ? The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v) (From https://nvd.nist.gov/vuln/detail/CVE-2020-1968).
According to CP sk92447 Status of OpenSSL, GAiA uses at least version 1.1.0d.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you sure you need it ? The attack can only be exploited if an implementation re-uses a DH secret across multiple TLS connections. Note that this issue only impacts DH ciphersuites and not ECDH ciphersuites. This issue affects OpenSSL 1.0.2 which is out of support and no longer receiving public updates. OpenSSL 1.1.1 is not vulnerable to this issue. Fixed in OpenSSL 1.0.2w (Affected 1.0.2-1.0.2v) (From https://nvd.nist.gov/vuln/detail/CVE-2020-1968).
According to CP sk92447 Status of OpenSSL, GAiA uses at least version 1.1.0d.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Given that a key is being reused across multiple connections, I don’t believe this is feasible to write a signature for.
However, that’s just my personal take.
