sk65269 - Check Point response to OpenSSH CVEs

Check Point response to OpenSSH CVEs

Product: Cloud Firewall, Multi-Domain Security Management, Security Gateways, Security Management
Version: Other
OS: Gaia
Last Modified: 2026-07-23

Solution

This article lists known CVEs for OpenSSH and their status for the OpenSSH packages used in Gaia OS. This article does not list all the known CVEs for OpenSSH but only those that Check Point explicitly checked.

[Expert@Hostname]# rpm -q --changelog $(rpm -qa | grep openssh) | grep CVE-2006-4924

Output should look like this:

- CVE-2006-4924 - prevent DoS on deattack detector (#207957)

Example:

[Expert@HostName:0]# rpm -qa | grep ssh
openssh-4.3p2-26.1.cp990150005
openssh-server-4.3p2-26.1.cp990150005
openssh-clients-4.3p2-26.1.cp990150005
CVE Comment
2026
CVE-2026-60002 Vulnerable but not exploitable - This should be done against trusted servers with StrictHostKeyChecking flag.
CVE-2026-60001 Vulnerable - Low Priority - Restrict SSH management access to trusted networks/objects.
CVE-2026-60000 Not vulnerable. GSSAPI support is not compiled into Gaia's OpenSSH build.
CVE-2026-59999 Vulnerable, not exploitable in current shipped config. Requires DisableForwarding yes + PermitTunnel yes together; Gaia's default config is no for both.
CVE-2026-59998 Not vulnerable - GSSAPI support is not compiled into Gaia's OpenSSH build.
CVE-2026-59997 Vulnerable, not exploitable in current shipped config. Gaia's shipped configuration uses the external sftp-server binary, not internal-sftp
CVE-2026-59996 Vulnerable, Not Exploitable. Requires a local-initiated remote-to-remote scp operation with an attacker-controlled source; no automated trigger identified in our review to date.
CVE-2026-59995 Vulnerable, Not Exploitable. Requires a local-initiated outbound sftp download from an attacker-controlled/spoofed server; no automated trigger identified in our review to date.
CVE-2026-35385 This is considered a low priority, as it requires the admin (root) to explicitly perform a malicious action (an SCP connection to a malicious server). Will be address upon OpenSSH upgrade in accordance with Check Point's product roadmap.
CVE-2026-35386 Vulnerable, not exploitable. The shipped with Gaia OS sshd_config does not use '%' token for configuration, which is required for exploitation.
CVE-2026-35387 Vulnerable, not exploitable: The shipped with Gaia OS sshd_config has no PubkeyAcceptedAlgorithms and/or HostbasedAcceptedAlgorithms configuration by default.
CVE-2026-35388 Vulnerable: not exploitable. The shipped with Gaia OS ssh_config (client config) has no ControlMaster or ControlPath configured, which are required to enable multiplexing. (Even if you enable this, the attack is still a local attack, which requires 'expert' access, which by itself grants root access level).
CVE-2026-35414 Vulnerable, Conditional. This is a combination of a very rare setup: certificate authentication configured (not regular public key auth) + the CA key must be trusted via the cert-authority option (not via TrustedUserCAKeys) + the principals = option must list more than one principal + the attacker must either control or compromise the CA.
CVE-2026-3497 Not vulnerable.
2025
CVE-2025-61985 Not vulnerable. The ProxyCommand SSH client option is not configured in our system, therefore it is disabled by default.
CVE-2025-61984 Not vulnerable. The ProxyCommand SSH client option is not configured in our system, therefore it is disabled by default.
CVE-2025-32728 This vulnerability is considered low priority as it requires the admin (root) to perform a malicious action. Refer to sk183394.
CVE-2025-26465 Not vulnerable. The VerifyHostKeyDNS SSH option is not configured in our system, therefore it is disabled by default.
CVE-2025-26466 Not vulnerable.
2024
CVE-2024-6409 Quantum products are not vulnerable. This vulnerability only affects the versions of OpenSSH shipped with Red Hat Enterprise Linux 9.
CVE-2024-6387 - Gaia OS - Not vulnerable. Gaia OS does not use the affected SSHD version. - Quantum Spark appliances with Gaia Embedded OS R81.10.x - Refer to sk182459.
CVE-2024-39894 Not vulnerable.
2023
CVE-2023-51767 Not vulnerable - It requires local access to initiate the attack vector, by that user is already an admin and can unleash havoc on his system without this CVE.
CVE-2023-51385 Not vulnerable - This vulnerability affects SSH-agent/ProxyComand and since Check Point products do not use SSH-agent/ProxyComand, there is no impact of this vulnerability on them.
CVE-2023-51384 Not vulnerable - This CVE refers to the SSH agent, which is not used in Gaia OS.
CVE-2023-48795 Refer to sk181833.
CVE-2023-38408 Not vulnerable - This CVE relates to forwarding the SSH-agent to a system controlled by an attacker. We do not use SSH-agent forwarding in Gaia OS. Note: You may configure SSH-agent forwarding manually, though this may be vulnerable. We will release a fix once it is available from Red Hat. In the meantime, customers that manually configured SSH-agent forwarding should review their configuration and make sure it is only forwarded to safe locations.
2021
CVE-2021-41617 Not vulnerable. Gaia OS does not have the AuthorizedKeysCommand or AuthorizedPrincipalsCommand directives in the SSHD configuration.
CVE-2021-36368 Not relevant. This is not considered to be a vulnerability (see also Red Hat's official response).
CVE-2021-28041 Not vulnerable.
2020
CVE-2020-15778 This is considered low priority because it requires the admin (root) to explicitly perform a malicious action (an SCP connection to a malicious server). There is currently no plan to fix this.
CVE-2020-14145 The fix is included in: - Jumbo Hotfix Accumulator for R80.40 starting from Take 158 - Jumbo Hotfix Accumulator for R81 starting from Take 68 - Jumbo Hotfix Accumulator for R81.10 starting from Take 55
2019
CVE-2019-16905 Not vulnerable.
CVE-2019-6109,
CVE-2019-6110,
CVE-2019-6111
The fix is included in: - Jumbo Hotfix Accumulator for R82 starting from Take 60 - Jumbo Hotfix Accumulator for R81.20 starting from Take 120
2018
CVE-2018-20685 The fix is included in: - Check Point Quantum R82 - Jumbo Hotfix Accumulator for R81.20 starting from Take 90 - Jumbo Hotfix Accumulator for R81.10 starting from Take 171
CVE-2018-15919 Not relevant - GSS API Authentication is not enabled on Gaia OS.
CVE-2018-15473 The fix is included in: - Jumbo Hotfix Accumulator for R80.20 from Take 43 - Jumbo Hotfix Accumulator for R80.10 from Take 185 - Jumbo Hotfix Accumulator for R77.30 from Take 348
2017
CVE-2017-15906 Not vulnerable.
2016
CVE-2016-8858 OpenSSH upstream does not consider this as a security issue.
CVE-2016-3115 Not relevant. Default setting in Check Point ' sshd_config' file is ' X11Forwarding=no'.
CVE-2016-0778 Not vulnerable (a hardened OpenSSH is used based on version 4.3). Refer to sk109636.
CVE-2016-0777 Not vulnerable (a hardened OpenSSH is used based on version 4.3). Refer to sk109636.
CVE-2016-6515 Not vulnerable.
CVE-2015-6565 Not vulnerable.
CVE-2016-6210 Low exploitability, contact Check Point Support.
CVE-2016-1907 Not vulnerable.
CVE-2016-1908 Not relevant.
CVE-2016-10009 Not relevant.
CVE-2016-10011 Not relevant.
CVE-2016-10012 Not relevant.
CVE-2016-10010 Not relevant.
CVE-2016-10708 Not vulnerable.
CVE-2016-20012 Not relevant - This is not considered to be a vulnerability (see also Red Hat's official response).
2015
CVE-2015-6565 Not vulnerable.
CVE-2015-6564 Not vulnerable.
CVE-2015-5600 Not vulnerable.
CVE-2015-5352 Not vulnerable.
CVE-2015-6563 Requires Expert access to the system. Refer to sk133652.
CVE-2015-8325 Not vulnerable.
2014
CVE-2014-2653 Not relevant.
CVE-2014-2532 Not relevant. Check Point does not use wildcards in ' sshd_config' file.
CVE-2014-1692 Not vulnerable.
2013
CVE-2013-2566 False positive. Refer to sk93395.
2012
CVE-2012-0814 Not relevant. This is a Debian OpenSSH vulnerability, and it does not affect Red Hat OpenSSH.
2011
CVE-2011-5000 Not vulnerable.
CVE-2011-4327 Not vulnerable.
2010
CVE-2010-4755 Not vulnerable.
CVE-2010-4478 Not vulnerable.
CVE-2010-5107 Low impact. Fixed in the R77.10 version.
2009
CVE-2009-2904 Not vulnerable.
2008
CVE-2008-5161 Not vulnerable. Very low impact. Refer to sk36343.
CVE-2008-3259 Not vulnerable.
CVE-2008-1657 Not vulnerable.
CVE-2008-1483 Not vulnerable since R70 GA.
CVE-2008-3234 Not relevant.
CVE-2008-4109 Not relevant.
CVE-2008-2359 Not relevant.
2007
CVE-2007-2768 Not vulnerable.
CVE-2007-4752 Not vulnerable.
CVE-2007-3102 Not vulnerable.
CVE-2007-2243 Not vulnerable.
CVE-2007-0726 Not relevant (bug in OpenSSH on Mac OS X).
2006
CVE-2006-5794 Not vulnerable since R65 GA.
CVE-2006-5052 Not vulnerable.
CVE-2006-5051 Not vulnerable. Refer to sk61744.
CVE-2006-4924 Not vulnerable. Refer to sk61744.
CVE-2006-0225 Not vulnerable.
CVE-2006-5229 Issue is not reproducible.
CVE-2006-4925 Not relevant (this is a client-side crash, not DoS).
2005
CVE-2005-2798 Not vulnerable.
CVE-2005-2797 Not vulnerable.
CVE-2005-2666 Vulnerability is not severe. The fix is too risky.
2004
CVE-2004-2069 Not vulnerable.
CVE-2004-1653 Configuration issue. Can be disabled if desired (by changing the ' AllowTcpForwarding' option in the /etc/ssh/sshd_config configuration file). However, it does not look relevant for SecurePlatform users.
2003
CVE-2003-1562 Not vulnerable since R70 GA.
CVE-2003-0787 Not vulnerable.
CVE-2003-0695 Not vulnerable since R70 GA.
CVE-2003-0693 Not vulnerable since R70 GA.
CVE-2003-0682 Not vulnerable since R70 GA.
CVE-2003-0386 Not vulnerable.

Clarifications:

Status Meaning
Not relevant - Either Check Point does not use the vulnerable code. - Or Check Point does not have this code in released versions. - Or Check Point changed the code in such a way that this vulnerability does not apply anymore.
Not vulnerable - The issue is not relevant to Check Point code (the affected code does not exist or is not used in Check Point software). - The issue was relevant to Check Point code and Check Point has already fixed it.
Relevant - The issue exists in Check Point code.