sk183168 - Check Point Response to CVE-2024-13176 - OpenSSL timing side-channel vulnerability in ECDSA signature computation
Check Point Response to CVE-2024-13176 - OpenSSL timing side-channel vulnerability in ECDSA signature computation
Please read this important update from Check Point.
Security Alert:
Low
Product: Multi-Domain Security Management, Security Gateways, Security Management
Version: R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Last Modified: 2025-08-11
Symptoms
- A vulnerability CVE-2024-13176 has been discovered in OpenSSL.
This issue is a timing side-channel vulnerability affecting the ECDSA signature computation. Under specific conditions, it may allow an attacker to recover the private key. The vulnerability is particularly relevant to certain elliptic curves, most notably the NIST P-521 curve, due to the presence of a measurable timing signal.
Despite its potential impact, successful exploitation requires either local access to the signing application or a high-speed, low-latency network connection. As a result, the overall severity of this vulnerability is considered low, and the likelihood of exploitation in real-world scenarios remains rare.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 25
- Jumbo Hotfix Accumulator for R81.20 starting from Take 101
- Jumbo Hotfix Accumulator for R81.10 starting from Take 177
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo file from the Gaia OS Server involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
Article Properties
Access Level: General
Severity: Low
Status: Approved
Date Created: 2025-02-20
Last Modified: 2025-08-11