sk182459 - Check Point Response to CVE-2024-6387 - OpenSSH Library RCE

Check Point Response to CVE-2024-6387 - OpenSSH Library RCE

Please read this important update from Check Point.

Security Alert:

High

Product: Spark Firewall
Version: R81.10.X
OS: Gaia Embedded
Platform: 1500, 1570R, 1575R, 1595R, 1600, 1800, 1900, 2000
Last Modified: 2025-02-09

Symptoms

Cause

A security regression ( CVE-2006-5051) was discovered in the OpenSSH server ( sshd) version 8.5p1. There is a race condition, which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

Solution

Important Notes

ssh -V

Solution

  1. Install the updated firmware image:
Download Package 1500
Appliances
1595R
Appliances
1600 / 1800 / 1900 / 2000
Appliances
R81.10.10 Build 996002993 (IMG) (IMG) (IMG)
R81.10.10 Build 996002993
for SmartUpdate
(TGZ) (TGZ) (TGZ)
R81.10.10 Build 996002993
Central Deployment package
for SmartConsole
(TAR) (TAR) (TAR)

Notes:

  1. On Locally Managed Quantum Spark appliances that run the R81.10.X versions, make sure the IPS protection "Multiple SSH Initial Connection Requests" is set to "Prevent" (this is the default in the "Recommended" and "Strict" Threat Prevention policies):
    1. In WebUI, click the Threat Prevention view > in the Threat Prevention section, click the Blade Control page.

    2. Enable the IPS blade.

    3. In the Policy section, select Recommended or Strict.

    4. In the bottom right corner, click Save.

    5. Click any other page in this section.

    6. In the Threat Prevention section, click the Blade Control page again.

    7. The IPS blade shows the status "Not up to date".

      After a short time, it must show the status "Up to date".

      You can hover over the status icon and in the tooltip, click Update now.

    8. In the left panel, in the Protections section, click the IPS Protections page.

    9. In the top right corner, search for: Multiple SSH Initial Connection Requests

    10. The Action column in this protection must show Prevent. If it shows any other value, then:

      1. Select this IPS protection.
      2. Click Edit.
      3. Select Prevent.
      4. Click Save.

Related Documentation

For more information, see sk65269 - Status of OpenSSH CVEs.

Revision History

Date Description
21 July 2024 Release of the improved firmware images Build 996002993.
17 July 2024 Removed the firmware images to improve them.
The improved firmware images will be added soon.
15 July 2024 Corrected the download link for Central Deployment package for SmartConsole for 1600 / 1800 / 1900 / 2000 Appliances.
14 July 2024 First release of this article.
Build 996002948.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.