Junglewise Threat Intelligence

CVE-2024-24919: Check Point Quantum Security Gateways Information Disclosure Vulnerability

CVE-2024-24919 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2024-05-30

Vendors: Check Point.

Executive brief

Check Point Quantum Security Gateways contain an information disclosure vulnerability that allows an unauthenticated attacker to read sensitive information. The vulnerability is exploitable on gateways connected to the internet with Remote Access VPN or Mobile Access Software Blades enabled. This issue has been observed being exploited in the wild.

Affected products

  • Check Point CloudGuard Network Security R80.40, R81, R81.10, R81.20
  • Check Point Quantum Security Gateway Firmware R80.40, R81, R81.10, R81.20
  • Check Point Quantum Spark Firmware R80.20, R80.40, R81, R81.10
  • Check Point Quantum Scalable Chassis

Timeline

  • 2024-05-30: disclosed: Initial publication date
  • 2024-05-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-05-30: patched: Security fix made available by vendor
  • 2024-05-30: exploited: Confirmed exploited in the wild at time of disclosure