sk182320 - Check Point Response to CVE-2024-2511 - OpenSSL unbounded memory growth with session handling in TLSv1.3
Check Point Response to CVE-2024-2511 - OpenSSL unbounded memory growth with session handling in TLSv1.3
Please read this important update from Check Point.
Security Alert:
- Severity: Low
- Product: Security Gateways, Security Management
- Version: R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
- Last Modified: 2025-02-09
Symptoms
- A vulnerability CVE-2024-2511 has been discovered in OpenSSL, a widely used open-source library for SSL/TLS encryption.
This vulnerability allows for initiating a Denial of Service (DoS) attack by triggering unbounded memory growth when processing TLSv1.3 sessions with certain non-default TLS server configurations. This configuration is only activated in the event of an error while creating a TLS session.
The severity of this CVE is low, and the likelihood of it occurring is rare.
Solution
This problem was fixed. The fix is included in:
- Check Point R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 79
- Jumbo Hotfix Accumulator for R81.10 starting from Take 158
- Jumbo Hotfix Accumulator for R81 starting from Take 106
If you choose not to upgrade, Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
Note: The "cpopenssl version" command would still show "OpenSSL 1.1.1w" because the fix for CVE-2024-2511 is a patch in the Check Point code and not an update for the OpenSSL package.
Article Properties
- Access Level: General
- Severity: Low
- Status: Approved
- Date Created: 2024-05-22
- Last Modified: 2025-02-09