sk182459 - Check Point Response to CVE-2024-6387 - OpenSSH Library RCE
Check Point Response to CVE-2024-6387 - OpenSSH Library RCE
Please read this important update from Check Point.
Security Alert:
High
Product: Spark Firewall
Version: R81.10.X
OS: Gaia Embedded
Platform: 1500, 1570R, 1575R, 1595R, 1600, 1800, 1900, 2000
Last Modified: 2025-02-09
Symptoms
- Remote Code Execution (RCE) vulnerability CVE-2024-6387 in the OpenSSH server (sshd) in glibc-based Linux systems can cause an unauthenticated RCE that grants full root access.
Cause
A security regression ( CVE-2006-5051) was discovered in the OpenSSH server ( sshd) version 8.5p1. There is a race condition, which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
Solution
Important Notes
Quantum Spark appliances that run the R81.10.x versions are vulnerable to CVE-2024-6387 because they use the OpenSSH version 8.5p1 that was discovered as vulnerable.
Quantum Spark appliances that run the versions R80.20.x or lower are not vulnerable to CVE-2024-6387 because they use Dropbear (and not OpenSSH).
Gaia OS versions (on all Check Point appliances and servers other than Quantum Spark) are not vulnerable to CVE-2024-6387 because they use the OpenSSH versions from 4.4p1 up to, but not including, 8.5p1 that are not vulnerable.
To check the current OpenSSH version in your Gaia Embedded / Gaia operating system, run this command in the Expert mode:
ssh -V
Solution
- Install the updated firmware image:
| Download Package | 1500 Appliances |
1595R Appliances |
1600 / 1800 / 1900 / 2000 Appliances |
| R81.10.10 Build 996002993 | (IMG) | (IMG) | (IMG) |
| R81.10.10 Build 996002993 for SmartUpdate |
(TGZ) | (TGZ) | (TGZ) |
| R81.10.10 Build 996002993 Central Deployment package for SmartConsole |
(TAR) | (TAR) | (TAR) |
Notes:
- If you already installed R81.10.10 Build 996002948, then we recommend to upgrade to the latest Build listed above.
- This firmware image also contains the fix for CVE-2024-24919.
- For the upgrade instructions, see the Quantum Spark 1500, 1600, 1800, 1900, and 2000 Appliance Series R81.10.X Locally Managed Administration Guide > section "To upgrade your appliance firmware manually".
- On Locally Managed Quantum Spark appliances that run the R81.10.X versions, make sure the IPS protection "Multiple SSH Initial Connection Requests" is set to "Prevent" (this is the default in the "Recommended" and "Strict" Threat Prevention policies):
In WebUI, click the Threat Prevention view > in the Threat Prevention section, click the Blade Control page.
Enable the IPS blade.
In the Policy section, select Recommended or Strict.
In the bottom right corner, click Save.
Click any other page in this section.
In the Threat Prevention section, click the Blade Control page again.
The IPS blade shows the status "Not up to date".
After a short time, it must show the status "Up to date".
You can hover over the status icon and in the tooltip, click Update now.
In the left panel, in the Protections section, click the IPS Protections page.
In the top right corner, search for: Multiple SSH Initial Connection Requests
The Action column in this protection must show Prevent. If it shows any other value, then:
- Select this IPS protection.
- Click Edit.
- Select Prevent.
- Click Save.
Related Documentation
For more information, see sk65269 - Status of OpenSSH CVEs.
Revision History
| Date | Description |
| 21 July 2024 | Release of the improved firmware images Build 996002993. |
| 17 July 2024 | Removed the firmware images to improve them. The improved firmware images will be added soon. |
| 15 July 2024 | Corrected the download link for Central Deployment package for SmartConsole for 1600 / 1800 / 1900 / 2000 Appliances. |
| 14 July 2024 | First release of this article. Build 996002948. |
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.