CVE-2024-24919

Confirmed PUBLISHED

Information disclosure

checkpoint · Check Point Quantum Gateway, Spark Gateway and CloudGuard Network
Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.6 High EPSS 100.0%

At a Glance

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

malware cisa nessus_scanner windows ransomware nuclei_scanner qilin ransomware
CVE Published
May 28, 2024
Exploitation Reported
May 30, 2024
CVSS
8.6 High
EPSS
100.0%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

49 version rows · page 1 of 2

Vendor Product Version Status
checkpoint
quantum_security_gateway_firmware

r80.40

Affected
checkpoint
quantum_security_gateway_firmware

r81

Affected
checkpoint
quantum_security_gateway_firmware

r81.10

Affected
checkpoint
quantum_security_gateway_firmware

r81.20

Affected
checkpoint
quantum_security_gateway_firmware

r80.40

Affected
checkpoint
quantum_security_gateway_firmware

r81

Affected
checkpoint
quantum_security_gateway_firmware

r81.10

Affected
checkpoint
quantum_security_gateway_firmware

r81.20

Affected
checkpoint
quantum_security_gateway_firmware

r80.40

Affected
checkpoint
quantum_security_gateway_firmware

r81

Affected
checkpoint
quantum_security_gateway_firmware

r81.10

Affected
checkpoint
quantum_security_gateway_firmware

r81.20

Affected
checkpoint
quantum_security_gateway_firmware

r80.40

Affected
checkpoint
quantum_security_gateway_firmware

r81

Affected
checkpoint
quantum_security_gateway_firmware

r81.10

Affected
checkpoint
quantum_security_gateway_firmware

r81.20

Affected
checkpoint
cloudguard_network

r80.40

Affected
checkpoint
cloudguard_network

r81

Affected
checkpoint
cloudguard_network

r81.10

Affected
checkpoint
cloudguard_network

r81.20

Affected
checkpoint
cloudguard_network

r80.40

Affected
checkpoint
cloudguard_network

r81

Affected
checkpoint
cloudguard_network

r81.10

Affected
checkpoint
cloudguard_network

r81.20

Affected
checkpoint
cloudguard_network

r80.40

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.