> Source: [sk182459](https://support.checkpoint.com/results/sk/sk182459)

# sk182459 - Check Point Response to CVE-2024-6387 - OpenSSH Library RCE

| Property | Value |
|----------|-------|
| Solution ID | sk182459 |
| Date Created | 2024-07-03 |
| Last Modified | 2025-02-09 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1570R, 1575R, 1500, 1900, 2000, 1600, 1800, 1595R |

## Symptoms

- Remote Code Execution (RCE) vulnerability [CVE-2024-6387](https://www.cve.org/CVERecord?id=CVE-2024-6387) in the OpenSSH server (sshd) in glibc-based Linux systems can cause an unauthenticated RCE that grants full root access.

## Cause

A security regression ([CVE-2006-5051](https://www.cve.org/CVERecord?id=CVE-2006-5051)) was discovered in the OpenSSH server (*sshd* ) version 8.5p1. There is a race condition, which can lead *sshd* to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

## Solution

### Important Notes

* Quantum Spark appliances that run the R81.10.x versions **are** vulnerable to CVE-2024-6387 because they use the OpenSSH version **8.5p1** that was discovered as vulnerable.

* Quantum Spark appliances that run the versions R80.20.x or lower are **not** vulnerable to CVE-2024-6387 because they use Dropbear (and not OpenSSH).

* Gaia OS versions (on all Check Point appliances and servers other than Quantum Spark) are **not** vulnerable to CVE-2024-6387 because they use the OpenSSH versions from 4.4p1 up to, but not including, 8.5p1 that are **not** vulnerable.

* To check the current OpenSSH version in your Gaia Embedded / Gaia operating system, run this command in the Expert mode:  
  `ssh -V`

### Solution

1. Install the updated firmware image:

   > |-----------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|
   > | **Download Package**                                                  | **1500 Appliances**                                                                                                      | **1595R Appliances**                                                                                                     | **1600 / 1800 / 1900 / 2000 Appliances**                                                                                 |
   > | R81.10.10 Build 996002993                                             | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/134275) (IMG) | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/134298) (IMG) | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/134302) (IMG) |
   > | R81.10.10 Build 996002993 for SmartUpdate                             | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/134320) (TGZ) | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/134321) (TGZ) | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/134322) (TGZ) |
   > | R81.10.10 Build 996002993 Central Deployment package for SmartConsole | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/134323) (TAR) | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/134324) (TAR) | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/134313) (TAR) |

   Notes:
   * If you already installed R81.10.10 Build 996002948, then we recommend to upgrade to the latest Build listed above.

   * This firmware image also contains the fix for [CVE-2024-24919](https://support.checkpoint.com/results/sk/sk182357).

   * For the upgrade instructions, see the [Quantum Spark 1500, 1600, 1800, 1900, and 2000 Appliance Series R81.10.X Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Backup-Restore-Upgrade-and-Other-System-Operatons.htm) \> section "To upgrade your appliance firmware manually".

2. On Locally Managed Quantum Spark appliances that run the R81.10.X versions, make sure the IPS protection "Multiple SSH Initial Connection Requests" is set to "Prevent" (this is the default in the "Recommended" and "Strict" Threat Prevention policies):

   1. In WebUI, click the **Threat Prevention** view \> in the **Threat Prevention** section, click the **Blade Control** page.

   2. Enable the **IPS** blade.

   3. In the **Policy** section, select **Recommended** or **Strict**.

   4. In the bottom right corner, click **Save**.

   5. Click any other page in this section.

   6. In the **Threat Prevention** section, click the **Blade Control** page again.

   7. The **IPS** blade shows the status "**Not up to date**".

      After a short time, it must show the status "**Up to date**".

      You can hover over the status icon and in the tooltip, click **Update now**.
   8. In the left panel, in the **Protections** section, click the **IPS Protections** page.

   9. In the top right corner, search for:

      **Multiple SSH Initial Connection Requests**
   10. The **Action** column in this protection must show **Prevent**.

       If it shows any other value, then:
       1. Select this IPS protection.

       2. Click **Edit**.

       3. Select **Prevent**.

       4. Click **Save**.

### Related Documentation

For more information, see [sk65269 - Status of OpenSSH CVEs](https://support.checkpoint.com/results/sk/sk65269).

### Revision History

Show / Hide revision history  

|--------------|-----------------------------------------------------------------------------------------------------------------------|
| Date         | Description                                                                                                           |
| 21 July 2024 | Release of the improved firmware images Build 996002993.                                                              |
| 17 July 2024 | Removed the firmware images to improve them. The improved firmware images will be added soon.                         |
| 15 July 2024 | Corrected the download link for Central Deployment package for SmartConsole for 1600 / 1800 / 1900 / 2000 Appliances. |
| 14 July 2024 | First release of this article. Build 996002948.                                                                       |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
