sk181427 - Check Point response to CVE-2022-4450, CVE-2022-4304 and and CVE-2023-2650

Check Point response to CVE-2022-4450, CVE-2022-4304 and and CVE-2023-2650

Product: Security Gateways, Security Management
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20
Last Modified: 2024-03-13

Symptoms

In OpenSSL 1.1.1, the version installed in R8X.XX Quantum Security Gateways and Management, this issue only affects the display of various objects, such as X.509 certificates. It is assumed not to lead to a Denial of Service, so R8X.XX Quantum Security Gateways and Management are considered unaffected in a way that would be a cause for concern.

Therefore, the severity is considered low.

Solution

This problem was fixed. The fix is included starting from:

The fix upgrades OpenSSL from 1.1.1t to 1.1.1u. Note: For other supported versions, new Jumbo Hotfix Accumulators will be released soon. This article will be updated accordingly.

Article Properties

Access Level: General
Status: Approved
Date Created: 2023-08-28
Last Modified: 2024-03-13