Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
D521815
Participant

Missing IPS protection?

We ran a health check (HCP), and it shows the following:

Protections Impact
IPS | Dynamic_Losant Arduino MQTT Client Buffer Overflow (CVE-2018-17614) | M^AGI$C3A | 6.02% |

We would like to inactivate this protection, but it is impossible to find using SmartConsole or GuiDBedit.
Any suggestions?

0 Kudos
13 Replies
the_rock
MVP Gold
MVP Gold

Let me search it in the lab and report back.

Andy

Best,
Andy
0 Kudos
the_rock
MVP Gold
MVP Gold

Just checked in both R81.20 and R82 and cant find that CVE anywhere, either in IPS or inspection settings. I see some protections for buffer overflow, but nothing with exact same name.

Andy

Best,
Andy
0 Kudos
PhoneBoy
Admin
Admin

I don't find the protection on my end, either.
Suggest a TAC case: https://help.checkpoint.com 

0 Kudos
Tal_Paz-Fridman
MVP Silver CHKP MVP Silver CHKP
MVP Silver CHKP

Can you add a screenshot of the output including the test name?

Thanks!

0 Kudos
D521815
Participant

Here comes a screenshot.

0 Kudos
Tal_Paz-Fridman
MVP Silver CHKP MVP Silver CHKP
MVP Silver CHKP

This is a protection that was available in the past. I'm checking if it has been removed and if we need to update HCP tests.

0 Kudos
D521815
Participant

We have ran Pattern Matcher statistics according to sk43733, and it shows the same result.

0 Kudos
Tal_Paz-Fridman
MVP Silver CHKP MVP Silver CHKP
MVP Silver CHKP

I sent the question to relevant owners in R&D.

It exists on the machine in various locations but perhaps it is not active.

Waiting for the reply from owners.

 

 

 

 

0 Kudos
Lesley
MVP Gold
MVP Gold

Is it not this but then the other way around? That it got removed instead of added. 

https://support.checkpoint.com/results/sk/sk171752

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
D521815
Participant

Have you heard anything from R&D yet?

0 Kudos
Tal_Paz-Fridman
MVP Silver CHKP MVP Silver CHKP
MVP Silver CHKP

They are currently looking at the issue.

Will update once I know more.

D521815
Participant

Any news?

Lesley
MVP Gold
MVP Gold

basic check to make sure IPS is ok. 

You have valid license (cplic print)?

IPS updated? (ips stat)

Version supported (cpinfo -y all)

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events