> Source: [sk183168](https://support.checkpoint.com/results/sk/sk183168)

# sk183168 - Check Point Response to CVE-2024-13176 - OpenSSL timing side-channel vulnerability in ECDSA signature computation

| Property | Value |
|----------|-------|
| Solution ID | sk183168 |
| Date Created | 2025-02-20 |
| Last Modified | 2025-08-11 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R82.10, R81.10 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Symptoms

- A vulnerability [CVE-2024-13176](https://www.cve.org/CVERecord?id=CVE-2024-13176) has been discovered in OpenSSL.

This issue is a timing side-channel vulnerability affecting the ECDSA signature computation. Under specific conditions, it may allow an attacker to recover the private key. The vulnerability is particularly relevant to certain elliptic curves, most notably the NIST P-521 curve, due to the presence of a measurable timing signal.

Despite its potential impact, successful exploitation requires either local access to the signing application or a high-speed, low-latency network connection. As a result, the overall severity of this vulnerability is considered low, and the likelihood of exploitation in real-world scenarios remains rare.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 25
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 101
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 177

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo file](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Gaia OS Server involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
