Executive brief
Check Point Quantum Security Gateways contain an information disclosure vulnerability that allows an unauthenticated attacker to read sensitive information. The vulnerability is exploitable on gateways connected to the internet with Remote Access VPN or Mobile Access Software Blades enabled. This issue has been observed being exploited in the wild.
Affected products
- Check Point CloudGuard Network Security R80.40, R81, R81.10, R81.20
- Check Point Quantum Security Gateway Firmware R80.40, R81, R81.10, R81.20
- Check Point Quantum Spark Firmware R80.20, R80.40, R81, R81.10
- Check Point Quantum Scalable Chassis
Timeline
- 2024-05-30: disclosed: Initial publication date
- 2024-05-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-05-30: patched: Security fix made available by vendor
- 2024-05-30: exploited: Confirmed exploited in the wild at time of disclosure