CVE-2024-24919
Check Point Quantum Security Gateways Information Disclosure Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 20 June 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
- CVSS 3.1
- 8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 99.98% probability · 100th percentile
- CISA KEV
- Listed 30 May 2024 · due 20 June 2024 · used in ransomware campaigns
- Weakness
- CWE-200
- Affected
- checkpoint/quantum spark firmware · checkpoint/quantum security gateway firmware · checkpoint/cloudguard network security
- Source
- cve@checkpoint.com
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://support.checkpoint.com/results/sk/sk182336 ; https://nvd.nist.gov/vuln/detail/CVE-2024-24919
References
- https://support.checkpoint.com/results/sk/sk182336Mitigation, Patch, Vendor Advisory
- https://support.checkpoint.com/results/sk/sk182336Mitigation, Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-24919US Government Resource
- https://www.mnemonic.io/resources/blog/advisory-check-point-remote-access-vpn-vulnerability-cve-2024-24919/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.