CVE-2024-24919: Check Point Quantum Security Gateways Information Disclosure Vulnerability
Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.
Other sources
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24919?
The severity level of CVE-2024-24919 has not been explicitly stated, but it involves an information disclosure vulnerability that can be serious in nature.
How do I fix CVE-2024-24919?
To fix CVE-2024-24919, apply the latest firmware updates for the affected Check Point Quantum Security Gateways as provided by the vendor.
Which versions of Check Point products are affected by CVE-2024-24919?
CVE-2024-24919 affects Check Point Quantum Security Gateways running the R80.40 and R81.x firmware versions.
What types of environments are impacted by CVE-2024-24919?
CVE-2024-24919 impacts environments with Check Point Quantum Security Gateways that have IPSec VPN, Remote Access VPN, or Mobile Access enabled and connected to the internet.
Is there any public exploit available for CVE-2024-24919?
As of now, there are indications that CVE-2024-24919 may have been actively exploited in attacks, highlighting the urgency for remediation.