CISOOnline

Check Point hole grants unauthenticated attackers full SmartConsole admin privileges



Challenges of IP address restrictions

While it can be technically challenging to keep the IP address allowlists that Check Point recommends current, given DHCP’s ability to easily change those addresses, Assaf Morag, a cybersecurity researcher at Flare, noted that specifically limiting access to a management console is far more critical than limiting overall external access.

“Implementing Trusted Clients as a per-IP allowlist is impractical,” he said, but that is not the case with restricting management access. “The more scalable solution is to restrict access based on trusted administrative network segments such as VPN pools, management VLANs, or jump hosts rather than maintaining lists of individual DHCP-assigned client addresses,” he explained. “That gives you the security benefit without creating a full-time administrative task. Maintaining allowlists for individual hosts is much more practical when those hosts have stable, predictable IP addresses, rather than dynamically assigned DHCP addresses.”

Pieter Arntz, malware intelligence researcher at Malwarebytes, also noted that the constantly changing nature of global IP addresses can prove annoying to IT teams. Stressing that he is not familiar with Check Point’s specific settings, he noted, “Certain settings are a nuisance when applied strictly, and at some point the IT staff gets tired of constantly tweaking and they abandon the most secure path.”



Source link