sk181879 - Vulnerability scan shows that Management Server supports weak SSL ciphers when connecting to various web portals over HTTPS
Vulnerability scan shows that Management Server supports weak SSL ciphers when connecting to various web portals over HTTPS
Product: Multi-Domain Security Management, Security Management
Version: R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2025-01-16
Symptoms
- A vulnerability scan shows that a Check Point Management Server supports weak SSL ciphers when connecting to various web portals over HTTPS (ports 443 and 19009) on the Management Server:
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
- TLS_RSA_WITH_AES_128_CBC_SHA256
- TLS_RSA_WITH_AES_128_GCM_SHA256
- TLS_RSA_WITH_AES_256_CBC_SHA256
- TLS_RSA_WITH_AES_256_GCM_SHA384
Solution
This problem was fixed. The fix is included starting from:
- Check Point Quantum R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 79
- Jumbo Hotfix Accumulator for R81.10 starting from Take 158
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo file from the Security Management Server / Multi-Domain Security Management Server involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
Important Notes:
This hotfix removes these weak SSL ciphers from the list of the supported ciphers on the Management Server. No need for any manual configuration.
This effectively hotfix removes SmartConsole support for Windows Server 2012 and Windows Server 2012 R2.
After installing this hotfix on the Management Server, SmartConsole on Windows Server 2012 versions would fail to connect to the Management Server with this error:
An error occurred while making the HTTP request to https://<IP_Address_of_Mgmt_Server>:19009/cpmws/LoginSvcRemote?wsdl. This could be due to the fact that the server certificate is not configured properly with HTTPSYS in the HTTPS case. This could also be caused by a mismatch of the security binding between the client and the server.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-01-30
Last Modified: 2025-01-16