> Source: [sk181427](https://support.checkpoint.com/results/sk/sk181427)

# sk181427 - Check Point response to CVE-2022-4450, CVE-2022-4304 and and CVE-2023-2650

| Property | Value |
|----------|-------|
| Solution ID | sk181427 |
| Date Created | 2023-08-28 |
| Last Modified | 2024-03-13 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R81.20, R81.10 (EOS), R81.20, R81 (EOS), R81.10 (EOS), R81 (EOS) |

## Symptoms

- * [CVE-2022-4450](https://www.cve.org/CVERecord?id=CVE-2022-4450): An OpenSSL vulnerability was discovered that enables the initiation of a Denial of Service (DoS) attack by submitting malicious PEM files for parsing. Because certificate parsing precedes certificate signature verification, a process that parses an externally supplied certificate could be subject to a denial of service attack.

* [CVE-2022-4304](https://www.cve.org/CVERecord?id=CVE-2022-4304): An OpenSSL vulnerability was discovered that enables the potential to initiate a timing-based side channel within the RSA Decryption implementation. This could be exploited to recover plaintext information over a network, following a Bleichenbacher-style attack methodology.

* [CVE-2023-2650](https://www.cve.org/CVERecord?id=CVE-2023-2650): An OpenSSL vulnerability was discovered that processing some specially crafted ASN.1 object identifiers or data containing them may be very slow.  

  In OpenSSL 1.1.1, the version installed in R8X.XX Quantum Security Gateways and Management, this issue only affects the display of various objects, such as X.509 certificates. It is assumed not to lead to a Denial of Service, so R8X.XX Quantum Security Gateways and Management are considered unaffected in a way that would be a cause for concern.   

  Therefore, the severity is considered low.

## Solution

This problem was fixed. The fix is included starting from:

* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 26
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 110
* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 89
* [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 211
* [R81.10.08 for Quantum Spark Appliances](https://support.checkpoint.com/results/sk/sk181079)

<br />

The fix upgrades OpenSSL from 1.1.1t to 1.1.1u.**Note**: For other supported versions, new Jumbo Hotfix Accumulators will be released soon. This article will be updated accordingly.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
