sk183101 - Check Point Response to CVE-2024-24911 - Out of Bounds read in the CPCA process on a Check Point Management Server
Check Point Response to CVE-2024-24911 - Out of Bounds read in the CPCA process on a Check Point Management Server
Please read this important update from Check Point.
Security Alert:
- Medium
Product: Multi-Domain Security Management, Security Management
Version: R81 (EOS), R81.10 (EOS), R81.20, R82
OS: Gaia
Last Modified: 2025-02-10
Symptoms
- In rare scenarios, the
cpcaprocess on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. - When the
cpcaprocess is down, VPN and SIC connectivity issues may occur if the CRL is not present in the Security Gateway's CRL cache, and a certificate needs to be verified by thecpcaprocess on the Management Server.
This issue received the ID CVE-2024-24911.
Cause
An Out-of-Bounds read may occur when processing certain HTTP "POST" requests to the Security Management Server / Domain Management Server to the TCP port 18264.
Repeated requests can cause a denial-of-service (DoS) of the cpca process and may lead it to exit unexpectedly with a core dump file.
Solution
This problem was fixed on the Check Point Management Server.
The fix is included starting from:
- Check Point R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 79
- Jumbo Hotfix Accumulator for R81.10 starting from Take 158
- Jumbo Hotfix Accumulator for R81 starting from Take 106
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
- Access Level: General
- Severity: Medium
- Status: Approved by TAC
- Date Created: 2025-02-02
- Last Modified: 2025-02-10