sk183244 - RADIUS authentication fails after installing Jumbo Hotfix Accumulator

RADIUS authentication fails after installing Jumbo Hotfix Accumulator

Product

Identity Awareness, Mobile Access / SSL VPN, Multi-Domain Security Management, Remote Access VPN, Security Gateways, Security Management

Version

R81.10 (EOS), R81.10.X, R81.20, R82, R82.10

OS

Gaia, Gaia Embedded

Last Modified

2025-09-29

Symptoms

The following example shows a RADIUS payload from a response packet meeting these criteria (the Message-Authenticator attribute value pair is the third attribute value pair contained in the payload):

RADIUS Protocol
    Code: Access-Accept (2)
    Packet identifier: 0xXX
    Length: 85
    Authenticator: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
    [This is a response to a request in frame 1]
    [Time from request: 0.083880000 seconds]
    Attribute Value Pairs
        AVP: t=Vendor-Specific(26) l=35 vnd=Open System Consultants(9048)
            Type: 26
            Length: 35
            Vendor ID: Open System Consultants (9048)
            VSA: t=Unknown-Attribute(18) l=29 val=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
                Type: 18
                Length: 29
                Unknown-Attribute: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
        AVP: t=Vendor-Specific(26) l=12 vnd=Check Point Software Technologies Ltd(2620)
            Type: 26
            Length: 12
            Vendor ID: Check Point Software Technologies Ltd (2620)
            VSA: t=Unknown-Attribute(230) l=6 val=00000001
                Type: 230
                Length: 6
                Unknown-Attribute: 00000001
        AVP: t=Message-Authenticator(80) l=18 val=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
            Type: 80
            Length: 18
            Message-Authenticator: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

check_respond_msg_auth: Comparison result: 1

act_on_response(rp=xxxxxx): Message-Authenticator integrity failed, also happened x times before

Cause

The hotfix that addresses Check Point's Response to CVE-2024-3596 - Blast-RADIUS attack expects the Message-Authenticator to be the first attribute value pair contained in RADIUS response packets when present.

This decision was based on the verbiage contained in the RFC draft Deprecating Insecure Practices in RADIUS published by the IETF.

However, RFC3579 "RADIUS (Remote Authentication Dial In User Service) Support For Extensible Authentication Protocol (EAP)" does not define a strict requirement for the Message-Authenticator to be the first attribute value pair contained in RADIUS response packets.

Solution

For Gaia appliances:

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

For Gaia Embedded appliances:

Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect these files:

  1. CPinfo file from the Management Server involved in the case.
  2. CPinfo file from the Security Gateway / each Cluster Member / Security Group involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General

Status: Approved by TAC

Date Created: 2025-03-13

Last Modified: 2025-09-29