> Source: [sk173513](https://support.checkpoint.com/results/sk/sk173513)

# sk173513 - Check Point Response to CVE-2021-30357 - partial information disclosure in SNX client for Linux before build 800008302

| Property | Value |
|----------|-------|
| Solution ID | sk173513 |
| Date Created | 2021-05-19 |
| Last Modified | 2025-02-09 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- SSL Network Extender client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partial disclosure of the files to which the user did not have access.

## Cause

SNX can accept files with connection commands. If such a file contains wrong commands, SNX prints the line with unrecognized command. Since SNX runs as ROOT, an attacker can supply any file on the system and get one line of its content. If the file contains sensitive information, the attacker can get part of it.

## Solution

**Install this hotfix package on your Security Gateway to upgrade the SNX to a non-vulnerable version:**

| **Security Gateway Version** |           **Hotfix Name**            |          **CPUSE Identifier for Online Package**          |                   **CPUSE Offline Package**                   |
|------------------------------|--------------------------------------|-----------------------------------------------------------|---------------------------------------------------------------|
| R80.10                       | R80_10_SNX_update_750                | Check_Point_R80_10_SNX_UPDATE_750_Bundle_T3_FULL.tgz      | [TGZ](https://support.checkpoint.com/results/download/115196) |
| R80.20                       | R80_20_SNX_update_584_main           | Check_Point_R80_20_SNX_UPDATE_584_MAIN_Bundle_T4_FULL.tgz | [TGZ](https://support.checkpoint.com/results/download/115198) |
| R80.20SP                     | R80_20SP_JHF_T310_SNX_MAIN_Bundle_T4 | Check_Point_R80_20SP_JHF_T310_SNX_MAIN_Bundle_T4_FULL.tgz | [TGZ](https://support.checkpoint.com/results/download/116840) |
| R80.30                       | R80_30_SNX_update_382_main           | Check_Point_R80_30_SNX_UPDATE_382_MAIN_Bundle_T6_FULL.tgz | [TGZ](https://support.checkpoint.com/results/download/115200) |
| R80.30SP                     | R80_30SP_JHF_T75_SNX_MAIN_Bundle_T2  | Check_Point_R80_30SP_JHF_T75_SNX_MAIN_Bundle_T2_FULL.tgz  | [TGZ](https://support.checkpoint.com/results/download/116842) |
| R80.40                       | R80_40_SNX_update_568_main           | Check_Point_R80_40_SNX_UPDATE_568_MAIN_Bundle_T3_FULL.tgz | [TGZ](https://support.checkpoint.com/results/download/115202) |
| R81                          | R81_SNX_update_111_main              | Check_Point_R81_SNX_UPDATE_111_MAIN_Bundle_T1_FULL.tgz    | [TGZ](https://support.checkpoint.com/results/download/115205) |

#### Information for Quantum Spark Appliances:

The fix is available for the 1500 models.

To upgrade the SNX Client, do one of these:

* Run this command on the appliance:

  `delete ssl-network-extender`
* Upgrade the firmware.

Note - The fix for 700 / 1100 / 1200R / 1400 models is planned.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
