> Source: [sk105062](https://support.checkpoint.com/results/sk/sk105062)

# sk105062 - Check Point Response to CVE-2015-0204 - TLS FREAK Attack

| Property | Value |
|----------|-------|
| Solution ID | sk105062 |
| Date Created | 2015-03-04 |
| Last Modified | 2025-02-09 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.20 |

## Symptoms

- On Tuesday, March 3, 2015, researchers disclosed a new SSL/TLS vulnerability - the FREAK attack. The vulnerability allows attackers to intercept HTTPS connections between vulnerable clients and vulnerable servers and force them to use the "export-grade" cryptography, which can then be decrypted or altered.   
There are several posts that discuss the attack in detail: [Matt Green](http://blog.cryptographyengineering.com/2015/03/attack-of-week-freak-or-factoring-nsa.html), [The Washington Post](http://www.washingtonpost.com/blogs/the-switch/wp/2015/03/03/freak-flaw-undermines-security-for-apple-and-google-users-researchers-discover/), and [Ed Felten](https://freedom-to-tinker.com/blog/felten/freak-attack-the-chickens-of-90s-crypto-restriction-come-home-to-roost/).   

A connection is vulnerable if both a vulnerable server accepts RSA_EXPORT cipher suites and a vulnerable client either offers an RSA_EXPORT suite or is using a version of OpenSSL that is vulnerable to [CVE-2015-0204](https://www.cve.org/CVERecord?id=CVE-2015-0204).

## Solution

**Table of Contents:**

1. Background
2. IPS Protection
3. Solution
4. Hotfix Packages
5. Revision History

(I) Background {#Background}
----------------------------

Check Point products **are *not* vulnerable** to the "FREAK" vulnerability (CVE-2015-0204) with the following exceptions:

* **Mobile Access Blade** - When using the Mobile Access Portal to access a 3rd party application server (usually, internal server), and if the 3rd party server is vulnerable to FREAK attack, then the connection may be susceptible to it.

  Notes:
  1. Connections between the Mobile Access Gateway and the application server will usually be within the corporate LAN, which makes these connections less likely to be exposed to this vulnerability.  

  2. The vulnerability still requires the attacker to be a Man-In-The-Middle (MITM).

  <br />

  <br />

* **IPSO Voyager with SSL** - By default IPSO does not configure HTTPS access to Voyager, so it is not vulnerable; but if this access is manually configured, IPSO would accept connections with export grade cipher suites.  
  Follow the below procedure as a workaround for this issue.

  <br />

* **Other Check Point products**   

  |---------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
  | Feature / Appliance                         | Status                                                                                                                                                                                                                         |
  | Gaia Portal / SecurePlatform WebUI          | **Not Vulnerable**                                                                                                                                                                                                             |
  | 600 / 1100 / Security Gateway 80 appliances | **Not Vulnerable**                                                                                                                                                                                                             |
  | X-Series Appliances (Blue Coat)             | **Not Vulnerable**                                                                                                                                                                                                             |
  | Edge / Safe@Office devices                  | **Not Vulnerable**                                                                                                                                                                                                             |
  | 61000 / 41000 Scalable Chassis with R76SP.X | Vulnerable when *Mobile Access Blade* is enabled and *Mobile Access Portal* is used. Fix was integrated into *Take_62* of [Jumbo Hotfix Accumulator for R76SP.10](http://supportcontent.checkpoint.com/solutions?id=sk103121). |
  | LOM card WebUI                              | Fixed in LOM firmware v2.2 (refer to [sk101241](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101241))                                                           |

(II) IPS Protection {#IPS Protection}
-------------------------------------

Check Point released "**[OpenSSL TLS Export Cipher Suite Downgrade (CVE-2015-0204)](http://www.checkpoint.com/defense/advisories/public/2015/cpai-2015-0223.html)** " IPS protection that protects customer environments.  
This protection is part of the Recommended profile. It enables organizations to add a layer of protection to their network while updating their systems with vendor-provided patches.

1. **CVEs**

   The IPS protection covers the following CVEs:
   * CVE-2015-0204  

   * CVE-2015-1637

<br />

1. **How can IPS best protect my environment?**

   Verify that the protection is set to "**`Prevent`**" mode in all IPS profiles.

   To enable the "[OpenSSL TLS Export Cipher Suite Downgrade (CVE-2015-0204)](http://www.checkpoint.com/defense/advisories/public/2015/cpai-2015-0223.html)" IPS protection in **`Prevent`** mode: right-click on this protection, click on '`Prevent on All Profiles`', and install policy on all Security Gateways.

Check Point also released the "[SSL Export Cipher Suite](http://www.checkpoint.com/defense/advisories/public/2015/cpai-2015-0226.html)" IPS protection that protects customer environments. This protection is not part of the Recommended profile. It will detect and block the usage of weak Export cipher suites

(III) Solution {#Solution}
--------------------------

It is highly recommended that the 3rd party Application Servers that are accessed through Mobile Access Blade will be configured to be not vulnerable to the FREAK attack.

In case Mobile Access Blade is configured to connect to a 3rd party Application Server that is vulnerable to FREAK attack, it is recommended to install the Hotfix below on the Security Gateway with enabled Mobile Access Blade. Refer to the "Hotfix Packages" section.

Check Point released a Hotfix for R77.20 and R77.10 (this hotfix is already integrated into **R80.10** and **R77.30** ). For other versions, [contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) (please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case).

Check Point continues the investigation and will update this SK article accordingly.

For **IPSO Voyager manually configured to work with SSL** the following workaround is available:{#IPSO Voyager}

1. Connect to command line.   

2. Open Clish:

   *\[root@HostName \~\]# clish*   

3. Check the current SSL setting:

   *IPSO:N\> show voyager ssl-level*
   * If this command returns "*VoyagerSSLLevel 0* ", then SSL is *not* used and IPSO Voyager is *not* vulnerable.   

   * If this command returns any value other than "0" (zero), then proceed to the next step.

   <br />

   <br />

4. Disable the weak "export" ciphers:

   *IPSO:N\> set voyager ssl-level 168*   
   *IPSO:N\> save config*   

5. Verify your configuration:

   *IPSO:N\> show voyager ssl-level*
   The output should show "*VoyagerSSLLevel 168*"

(IV) Hotfix Packages {#Hotfix Packages}
---------------------------------------

Hotfix packages are available for **R77.20 and R77.10** (this hotfix is already integrated into **R77.30**).

**Notes:**

* For other versions, [contact Check Point Support](http://www.checkpoint.com/services/contact/index.html). For faster resolution and verification, please collect [CPinfo file](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the involved machine.
* To check which Hotfixes are installed on your Check Point machine refer to [sk72800 - How to check which Hotfixes are installed on Check Point machine](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk72800). You can use this to also check whether this Hotfix was successfully installed.
* In cluster environment, hotfix must be installed on all members of the cluster.
* In Management HA environment, hotfix must be installed on both Management Servers.

**Instructions:**

* **Hotfix package for R77.20 and R77.10 - Gaia OS using CPUSE (Check Point Update Service Engine)**  

  * **Online installation**

    1. Connect to the Gaia Portal on your Check Point machine and navigate to ***Upgrades (CPUSE)*** pane (in Gaia R77.20) / to ***Software Updates*** pane (in Gaia R77.10 and lower) - click on ***Status and Actions***.
    2. Select the hotfix package ***\<Version\> Hotfix for sk105062 (TLS FREAK Attack (CVE-2015-0204))*** - click on ***Install Update*** button on the toolbar.
    3. When using CPUSE everything is being done automatically, so if a reboot is needed, the machine will automatically reboot. There is no need to reboot or run *cpstop*manually.

    <br />

    <br />

  * **Offline installation**

    *In order to download these packages you will need to have a [Software Subscription or Active Support plan](http://www.checkpoint.com/services/techsupport/index.html).*

    |--------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------|
    |              | R77.20                                                                                                                                                        | R77.10                                                                                                                                                        |
    | Gaia - CPUSE | [![](https://sc1.checkpoint.com/sc/images/download-m.png "R77.20 Gaia (CPUSE offline package)")](http://supportcontent.checkpoint.com/file_download?id=40410) | [![](https://sc1.checkpoint.com/sc/images/download-m.png "R77.10 Gaia (CPUSE offline package)")](http://supportcontent.checkpoint.com/file_download?id=40464) |

  **Notes:**
  * For detailed installation instructions, refer to [sk92449: CPUSE - Gaia Software Updates (including Gaia Software Updates Agent)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE) - section "*(4) How to work with CPUSE*".
  * Hotfix has to be installed on **all Security Gateways running Gaia OS**.

  <br />

  <br />

* **Hotfix package for R77.20 and R77.10 - Gaia OS (manual installation in Command Line)**  

  *In order to download these packages, you will need to have a [Software Subscription or Active Support plan](http://www.checkpoint.com/services/techsupport/index.html).*  
  [Click here](https://supportcenter.checkpoint.com//supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105062#CLI_anchor_for_Mobile_App) to see the available downloads.  
  >
  > |------------|---------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------|
  > |            | R77.20                                                                                                                                | R77.10                                                                                                                                |
  > | Gaia - CLI | [![](https://sc1.checkpoint.com/sc/images/download-m.png "R77.20 Gaia")](http://supportcontent.checkpoint.com/file_download?id=40409) | [![](https://sc1.checkpoint.com/sc/images/download-m.png "R77.10 Gaia")](http://supportcontent.checkpoint.com/file_download?id=40465) |

  <br />

  <br />

  **Procedure:**
  1. Hotfix has to be installed on **Security Gateways running Gaia OS**.
  2. Download the relevant hotfix package from the table below, transfer the hotfix package to the machine and unpack it:  
     **`[Expert@HostName]# tar -zxvf Check_Point_Hotfix_`*VERSION* `_`*OS*`_sk105062.tgz`**
  3. Install the hotfix:  
     **`[Expert@HostName]# ./UnixInstallScript`**   
     Note: The script will stop all of Check Point services ('`cpstop`') - read the output on the screen.
  4. Reboot is required.
  {#CLI_anchor_for_Mobile_App}
{#CLI_anchor_for_Mobile_App}

These hotfix packages also include the following fixes:

* [sk103683 - Check Point response to TLS 1.x padding vulnerability (CVE-2014-8730)](http://supportcontent.checkpoint.com/solutions?id=sk103683)  

* [sk102989 - Check Point response to the POODLE Bites vulnerability (CVE-2014-3566)](http://supportcontent.checkpoint.com/solutions?id=sk102989)  

* [sk101708 - Anti-Virus and Threat Emulation blades miss inspection](http://supportcontent.checkpoint.com/solutions?id=sk10170)

(V) Revision History {#Revision History}
----------------------------------------

Show / Hide the revision history   

|--------------|--------------------------------------------------------------------------------------|
| Date         | Description                                                                          |
| 16 Nov 2017  | Added fix for LOM card                                                               |
| 01 July 2015 | Updated instructions for IPSO Voyager                                                |
| 30 May 2015  | Added a note that the offered hotfix is already integrated into R77.30               |
| 25 May 2015  | Updated status of fix availability for 61000 / 41000 Security Systems                |
| 30 Mar 2015  | Additional fixes were indicated                                                      |
| 22 Mar 2015  | Updated status of 61000 / 41000 Security Systems                                     |
| 11 Mar 2015  | Updated status of X-Series Appliances / Edge / Safe@Office devices as Not Vulnerable |
| 08 Mar 2015  | Added HotFix for R77.10                                                              |
| 08 Mar 2015  | Added workaround for IPSO Voyager with SSL                                           |
| 06 Mar 2015  | First release of this article                                                        |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
