sk181833 - Check Point response to CVE-2023-48795

Check Point response to CVE-2023-48795

Product

Check Point Appliances, Maestro HyperScale Firewall, Scalable Chassis

Version

R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20

Last Modified

2026-07-12

Symptoms

Read more about CVE-2023-48795 here.

Solution

This problem was fixed. The fix is included starting from:

Check Point recommends to always upgrade to the Recommended version.

If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version. A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect these files:

  1. CPinfo file from the Management Server involved in the case.
  2. CPinfo file from the Security Gateway / each Cluster Member involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

Workaround for Versions R81.20 and Earlier

For versions R81.20 and earlier, follow the relevant procedure below to disable the "chacha20-poly1305" cipher in OpenSSH.

Procedure for R81.10 and R81.20 Security Gateways / Management Servers / Log Servers

Note: For R81.10 Scalable Platforms, make the changes in Gaia Clish on each Security Group Member (SGM). For R81.20 Scalable platforms, the commands in the procedure are supported in Gaia gClish.

  1. Connect to the command line on the appliance.
  2. Show the list of enabled ciphers. In the list, look for _chacha20-poly1305@openssh.com._ show ssh server cipher enabled
  3. Set the chacha20-poly1305@openssh.com cipher to off. set ssh server cipher chacha20-poly1305@openssh.com off
  4. Save the configuration. save config

Procedure for R80.40 and R81 - Security Gateways / Management Servers / Log Servers that run Gaia OS

  1. Connect to the command line on the appliance.
  2. Log in to the Expert mode.
  3. Get the list of the currently enabled ciphers and paste it into a plain-text editor (like Notepad++) on your computer: sshd -T -C addr=localhost | grep -i ciphers
  4. On your computer, in the plain-text editor, edit the list of the enabled ciphers to remove the unwanted ciphers. Important Note - If you do not see the unwanted cipher in this list, then your Gaia OS is not vulnerable. Stop the procedure.

Example:

  1. Back up the current SSH configuration file:
    • R81, or R80.40 Jumbo Hotfix Take 83 and higher: cp -v /etc/ssh/templates/sshd_config.templ{,_BKP}
    • R80.40, or R80.40 Jumbo Hotfix Take 78 and lower: cp -v /etc/ssh/sshd_config{,_BKP}
  2. Edit the current SSH configuration file:
    • R81, or R80.40 Jumbo Hotfix Take 83 and higher: vi /etc/ssh/templates/sshd_config.templ
    • R80.40, or R80.40 Jumbo Hotfix Take 78 and lower: vi /etc/ssh/sshd_config
  3. Look for the ciphers line. Example: ciphers 3des-cbc,blowfish-cbc,cast128-cbc,aes128-cbc,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
  4. If this ciphers line exists in the SSH configuration file, then delete the current line and paste the modified ciphers line from your computer from the plain-text editor.
  5. If this ciphers line does not exist in the SSH configuration file, then paste the modified ciphers line from your computer from the plain-text editor above the line Match address.
  6. Save the changes in the file, and exit Vi editor.
  7. On R81, or R80.40 Jumbo Hotfix Take 83 and higher: Run this command: /bin/sshd_template_xlate < /config/active
  8. Restart the SSH server: service sshd restart

Procedure for R81 Scalable Platforms (Maestro and Chassis)

  1. Connect to the command line on the Security Group.
  2. If your default shell is Gaia gClish, then go to the Expert mode: expert
  3. Get the list of the currently enabled ciphers and paste it into a plain-text editor (like Notepad++) on your computer: sshd -T -C addr=localhost | grep -i ciphers
  4. On your computer, in the plain-text editor, edit the list of the enabled ciphers to remove the unwanted ciphers. Important Note - If you do not see the unwanted cipher in this list, then your Gaia OS is not vulnerable. Stop the procedure.

Example:

  1. Back up the current SSH configuration file: g_all cp -v /etc/ssh/sshd_config{,_BKP}
  2. Edit the current SSH configuration file: vi /etc/ssh/sshd_config
  3. Look for the ciphers line. Example: ciphers 3des-cbc,blowfish-cbc,cast128-cbc,aes128-cbc,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
  4. If this ciphers line exists in the SSH configuration file, then delete the current line and paste the modified ciphers line from your computer from the plain-text editor.
  5. If this ciphers line does not exist in the SSH configuration file, then paste the modified ciphers line from your computer from the plain-text editor above the line Match address.
  6. Save the changes in the file, and exit Vi editor.
  7. Copy the modified file to all Security Group Members: asg_cp2blades -b all /etc/ssh/sshd_config
  8. Restart the SSH server: g_all service sshd restart

Additional Notes

Example: ciphers 3des-cbc,blowfish-cbc,cast128-cbc,aes128-cbc,aes192-cbc,aes256-cbc,rijndael-cbc@lysator.liu.se

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.