sk65269 - Check Point response to OpenSSH CVEs
Check Point response to OpenSSH CVEs
Product: Cloud Firewall, Multi-Domain Security Management, Security Gateways, Security Management
Version: Other
OS: Gaia
Last Modified: 2026-07-23
Solution
This article lists known CVEs for OpenSSH and their status for the OpenSSH packages used in Gaia OS. This article does not list all the known CVEs for OpenSSH but only those that Check Point explicitly checked.
- To check if the installed OpenSSH package is patched against a CVE (e.g., for CVE-2006-4924), run:
[Expert@Hostname]# rpm -q --changelog $(rpm -qa | grep openssh) | grep CVE-2006-4924
Output should look like this:
- CVE-2006-4924 - prevent DoS on deattack detector (#207957)
- You can use the "
rpm -qa | grep ssh" command to verify the OpenSSH package version. This version can be correlated with CVE fixes integrated.
Example:
[Expert@HostName:0]# rpm -qa | grep ssh
openssh-4.3p2-26.1.cp990150005
openssh-server-4.3p2-26.1.cp990150005
openssh-clients-4.3p2-26.1.cp990150005
| CVE | Comment |
| 2026 | |
| CVE-2026-60002 | Vulnerable but not exploitable - This should be done against trusted servers with StrictHostKeyChecking flag. |
| CVE-2026-60001 | Vulnerable - Low Priority - Restrict SSH management access to trusted networks/objects. |
| CVE-2026-60000 | Not vulnerable. GSSAPI support is not compiled into Gaia's OpenSSH build. |
| CVE-2026-59999 | Vulnerable, not exploitable in current shipped config. Requires DisableForwarding yes + PermitTunnel yes together; Gaia's default config is no for both. |
| CVE-2026-59998 | Not vulnerable - GSSAPI support is not compiled into Gaia's OpenSSH build. |
| CVE-2026-59997 | Vulnerable, not exploitable in current shipped config. Gaia's shipped configuration uses the external sftp-server binary, not internal-sftp |
| CVE-2026-59996 | Vulnerable, Not Exploitable. Requires a local-initiated remote-to-remote scp operation with an attacker-controlled source; no automated trigger identified in our review to date. |
| CVE-2026-59995 | Vulnerable, Not Exploitable. Requires a local-initiated outbound sftp download from an attacker-controlled/spoofed server; no automated trigger identified in our review to date. |
| CVE-2026-35385 | This is considered a low priority, as it requires the admin (root) to explicitly perform a malicious action (an SCP connection to a malicious server). Will be address upon OpenSSH upgrade in accordance with Check Point's product roadmap. |
| CVE-2026-35386 | Vulnerable, not exploitable. The shipped with Gaia OS sshd_config does not use '%' token for configuration, which is required for exploitation. |
| CVE-2026-35387 | Vulnerable, not exploitable: The shipped with Gaia OS sshd_config has no PubkeyAcceptedAlgorithms and/or HostbasedAcceptedAlgorithms configuration by default. |
| CVE-2026-35388 | Vulnerable: not exploitable. The shipped with Gaia OS ssh_config (client config) has no ControlMaster or ControlPath configured, which are required to enable multiplexing. (Even if you enable this, the attack is still a local attack, which requires 'expert' access, which by itself grants root access level). |
| CVE-2026-35414 | Vulnerable, Conditional. This is a combination of a very rare setup: certificate authentication configured (not regular public key auth) + the CA key must be trusted via the cert-authority option (not via TrustedUserCAKeys) + the principals = option must list more than one principal + the attacker must either control or compromise the CA. |
| CVE-2026-3497 | Not vulnerable. |
| 2025 | |
| CVE-2025-61985 | Not vulnerable. The ProxyCommand SSH client option is not configured in our system, therefore it is disabled by default. |
| CVE-2025-61984 | Not vulnerable. The ProxyCommand SSH client option is not configured in our system, therefore it is disabled by default. |
| CVE-2025-32728 | This vulnerability is considered low priority as it requires the admin (root) to perform a malicious action. Refer to sk183394. |
| CVE-2025-26465 | Not vulnerable. The VerifyHostKeyDNS SSH option is not configured in our system, therefore it is disabled by default. |
| CVE-2025-26466 | Not vulnerable. |
| 2024 | |
| CVE-2024-6409 | Quantum products are not vulnerable. This vulnerability only affects the versions of OpenSSH shipped with Red Hat Enterprise Linux 9. |
| CVE-2024-6387 | - Gaia OS - Not vulnerable. Gaia OS does not use the affected SSHD version. - Quantum Spark appliances with Gaia Embedded OS R81.10.x - Refer to sk182459. |
| CVE-2024-39894 | Not vulnerable. |
| 2023 | |
| CVE-2023-51767 | Not vulnerable - It requires local access to initiate the attack vector, by that user is already an admin and can unleash havoc on his system without this CVE. |
| CVE-2023-51385 | Not vulnerable - This vulnerability affects SSH-agent/ProxyComand and since Check Point products do not use SSH-agent/ProxyComand, there is no impact of this vulnerability on them. |
| CVE-2023-51384 | Not vulnerable - This CVE refers to the SSH agent, which is not used in Gaia OS. |
| CVE-2023-48795 | Refer to sk181833. |
| CVE-2023-38408 | Not vulnerable - This CVE relates to forwarding the SSH-agent to a system controlled by an attacker. We do not use SSH-agent forwarding in Gaia OS. Note: You may configure SSH-agent forwarding manually, though this may be vulnerable. We will release a fix once it is available from Red Hat. In the meantime, customers that manually configured SSH-agent forwarding should review their configuration and make sure it is only forwarded to safe locations. |
| 2021 | |
| CVE-2021-41617 | Not vulnerable. Gaia OS does not have the AuthorizedKeysCommand or AuthorizedPrincipalsCommand directives in the SSHD configuration. |
| CVE-2021-36368 | Not relevant. This is not considered to be a vulnerability (see also Red Hat's official response). |
| CVE-2021-28041 | Not vulnerable. |
| 2020 | |
| CVE-2020-15778 | This is considered low priority because it requires the admin (root) to explicitly perform a malicious action (an SCP connection to a malicious server). There is currently no plan to fix this. |
| CVE-2020-14145 | The fix is included in: - Jumbo Hotfix Accumulator for R80.40 starting from Take 158 - Jumbo Hotfix Accumulator for R81 starting from Take 68 - Jumbo Hotfix Accumulator for R81.10 starting from Take 55 |
| 2019 | |
| CVE-2019-16905 | Not vulnerable. |
| CVE-2019-6109, CVE-2019-6110, CVE-2019-6111 |
The fix is included in: - Jumbo Hotfix Accumulator for R82 starting from Take 60 - Jumbo Hotfix Accumulator for R81.20 starting from Take 120 |
| 2018 | |
| CVE-2018-20685 | The fix is included in: - Check Point Quantum R82 - Jumbo Hotfix Accumulator for R81.20 starting from Take 90 - Jumbo Hotfix Accumulator for R81.10 starting from Take 171 |
| CVE-2018-15919 | Not relevant - GSS API Authentication is not enabled on Gaia OS. |
| CVE-2018-15473 | The fix is included in: - Jumbo Hotfix Accumulator for R80.20 from Take 43 - Jumbo Hotfix Accumulator for R80.10 from Take 185 - Jumbo Hotfix Accumulator for R77.30 from Take 348 |
| 2017 | |
| CVE-2017-15906 | Not vulnerable. |
| 2016 | |
| CVE-2016-8858 | OpenSSH upstream does not consider this as a security issue. |
| CVE-2016-3115 | Not relevant. Default setting in Check Point ' sshd_config' file is ' X11Forwarding=no'. |
| CVE-2016-0778 | Not vulnerable (a hardened OpenSSH is used based on version 4.3). Refer to sk109636. |
| CVE-2016-0777 | Not vulnerable (a hardened OpenSSH is used based on version 4.3). Refer to sk109636. |
| CVE-2016-6515 | Not vulnerable. |
| CVE-2015-6565 | Not vulnerable. |
| CVE-2016-6210 | Low exploitability, contact Check Point Support. |
| CVE-2016-1907 | Not vulnerable. |
| CVE-2016-1908 | Not relevant. |
| CVE-2016-10009 | Not relevant. |
| CVE-2016-10011 | Not relevant. |
| CVE-2016-10012 | Not relevant. |
| CVE-2016-10010 | Not relevant. |
| CVE-2016-10708 | Not vulnerable. |
| CVE-2016-20012 | Not relevant - This is not considered to be a vulnerability (see also Red Hat's official response). |
| 2015 | |
| CVE-2015-6565 | Not vulnerable. |
| CVE-2015-6564 | Not vulnerable. |
| CVE-2015-5600 | Not vulnerable. |
| CVE-2015-5352 | Not vulnerable. |
| CVE-2015-6563 | Requires Expert access to the system. Refer to sk133652. |
| CVE-2015-8325 | Not vulnerable. |
| 2014 | |
| CVE-2014-2653 | Not relevant. |
| CVE-2014-2532 | Not relevant. Check Point does not use wildcards in ' sshd_config' file. |
| CVE-2014-1692 | Not vulnerable. |
| 2013 | |
| CVE-2013-2566 | False positive. Refer to sk93395. |
| 2012 | |
| CVE-2012-0814 | Not relevant. This is a Debian OpenSSH vulnerability, and it does not affect Red Hat OpenSSH. |
| 2011 | |
| CVE-2011-5000 | Not vulnerable. |
| CVE-2011-4327 | Not vulnerable. |
| 2010 | |
| CVE-2010-4755 | Not vulnerable. |
| CVE-2010-4478 | Not vulnerable. |
| CVE-2010-5107 | Low impact. Fixed in the R77.10 version. |
| 2009 | |
| CVE-2009-2904 | Not vulnerable. |
| 2008 | |
| CVE-2008-5161 | Not vulnerable. Very low impact. Refer to sk36343. |
| CVE-2008-3259 | Not vulnerable. |
| CVE-2008-1657 | Not vulnerable. |
| CVE-2008-1483 | Not vulnerable since R70 GA. |
| CVE-2008-3234 | Not relevant. |
| CVE-2008-4109 | Not relevant. |
| CVE-2008-2359 | Not relevant. |
| 2007 | |
| CVE-2007-2768 | Not vulnerable. |
| CVE-2007-4752 | Not vulnerable. |
| CVE-2007-3102 | Not vulnerable. |
| CVE-2007-2243 | Not vulnerable. |
| CVE-2007-0726 | Not relevant (bug in OpenSSH on Mac OS X). |
| 2006 | |
| CVE-2006-5794 | Not vulnerable since R65 GA. |
| CVE-2006-5052 | Not vulnerable. |
| CVE-2006-5051 | Not vulnerable. Refer to sk61744. |
| CVE-2006-4924 | Not vulnerable. Refer to sk61744. |
| CVE-2006-0225 | Not vulnerable. |
| CVE-2006-5229 | Issue is not reproducible. |
| CVE-2006-4925 | Not relevant (this is a client-side crash, not DoS). |
| 2005 | |
| CVE-2005-2798 | Not vulnerable. |
| CVE-2005-2797 | Not vulnerable. |
| CVE-2005-2666 | Vulnerability is not severe. The fix is too risky. |
| 2004 | |
| CVE-2004-2069 | Not vulnerable. |
| CVE-2004-1653 | Configuration issue. Can be disabled if desired (by changing the ' AllowTcpForwarding' option in the /etc/ssh/sshd_config configuration file). However, it does not look relevant for SecurePlatform users. |
| 2003 | |
| CVE-2003-1562 | Not vulnerable since R70 GA. |
| CVE-2003-0787 | Not vulnerable. |
| CVE-2003-0695 | Not vulnerable since R70 GA. |
| CVE-2003-0693 | Not vulnerable since R70 GA. |
| CVE-2003-0682 | Not vulnerable since R70 GA. |
| CVE-2003-0386 | Not vulnerable. |
Clarifications:
| Status | Meaning |
| Not relevant | - Either Check Point does not use the vulnerable code. - Or Check Point does not have this code in released versions. - Or Check Point changed the code in such a way that this vulnerability does not apply anymore. |
| Not vulnerable | - The issue is not relevant to Check Point code (the affected code does not exist or is not used in Check Point software). - The issue was relevant to Check Point code and Check Point has already fixed it. |
| Relevant | - The issue exists in Check Point code. |