sk183168 - Check Point Response to CVE-2024-13176 - OpenSSL timing side-channel vulnerability in ECDSA signature computation

Check Point Response to CVE-2024-13176 - OpenSSL timing side-channel vulnerability in ECDSA signature computation

Please read this important update from Check Point.

Security Alert:

Low

Product: Multi-Domain Security Management, Security Gateways, Security Management
Version: R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Last Modified: 2025-08-11

Symptoms

This issue is a timing side-channel vulnerability affecting the ECDSA signature computation. Under specific conditions, it may allow an attacker to recover the private key. The vulnerability is particularly relevant to certain elliptic curves, most notably the NIST P-521 curve, due to the presence of a measurable timing signal.

Despite its potential impact, successful exploitation requires either local access to the signing application or a high-speed, low-latency network connection. As a result, the overall severity of this vulnerability is considered low, and the likelihood of exploitation in real-world scenarios remains rare.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo file from the Gaia OS Server involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

Article Properties

Access Level: General
Severity: Low
Status: Approved
Date Created: 2025-02-20
Last Modified: 2025-08-11