CVE-2024-24919
Confirmed PUBLISHEDInformation disclosure
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
- CVE Published
- May 28, 2024
- Exploitation Reported
- May 30, 2024
- CVSS
- 8.6 High
- EPSS
- 100.0%
Affected Versions
49 version rows · page 1 of 2
| Vendor | Product | Version | Status |
|---|---|---|---|
| checkpoint |
quantum_security_gateway_firmware
|
r80.40 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r81 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r81.10 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r81.20 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r80.40 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r81 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r81.10 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r81.20 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r80.40 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r81 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r81.10 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r81.20 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r80.40 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r81 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r81.10 |
Affected |
| checkpoint |
quantum_security_gateway_firmware
|
r81.20 |
Affected |
| checkpoint |
cloudguard_network
|
r80.40 |
Affected |
| checkpoint |
cloudguard_network
|
r81 |
Affected |
| checkpoint |
cloudguard_network
|
r81.10 |
Affected |
| checkpoint |
cloudguard_network
|
r81.20 |
Affected |
| checkpoint |
cloudguard_network
|
r80.40 |
Affected |
| checkpoint |
cloudguard_network
|
r81 |
Affected |
| checkpoint |
cloudguard_network
|
r81.10 |
Affected |
| checkpoint |
cloudguard_network
|
r81.20 |
Affected |
| checkpoint |
cloudguard_network
|
r80.40 |
Affected |
CVE References
- support.checkpoint.com/results/sk/sk182336 support.checkpoint.com · CVE Record https://support.checkpoint.com/results/sk/sk182336
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2024-05-30 00:00 UTC |
| The Shadowserver | 2026-05-31 00:00 UTC |
| Rapid7 | 2026-06-08 19:21 UTC |
Scanner Artifacts
Nuclei and Metasploit references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-24919.yaml | Apr 25, 2025 |
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Exploitation Status
Exploited in the wild
Recorded 2024-05-30 00:00:00 UTC · CISA
Used in qilin ransomware malware
Recorded 2024-05-30 00:00:00 UTC · CISA
Proof of concept available
Recorded 2024-05-31 10:18:36 UTC · GitHub
Weaknesses (CWE)
-
Exposure of Sensitive Information to an Unauthorized Actor
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-24919.yaml | Apr 25, 2025 |
| Nessus | https://www.tenable.com/plugins/nessus/198147 | May 30, 2024 |
Recent Mentions
Rapid7 · Jun 08, 2026
OverviewOn June 8, 2026, Check Point published a security advisory for CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN, Mobile Access, and Spark Firewall products. The vulnerability affects deployments configured to use the deprecated IKEv1 key exchange protocol where gateways accept legacy Remote Access clients and do not require a machine certificate for connections.CVE-2026-50751, classified as improper authentication (CWE-287), has a CVSS score of 9.3. The vulnerability stems from a logic flow weakness in how Remote Access and Mobile Access components validate certificates during IKEv1 key exchange; successful exploitation allows an unauthenticated attacker to establish a VPN session without providing valid credentials. Per the vendor, additional post-authentication activity is required to access internal resources or escalate privileges.Check Point has indicated that CVE-2026-50751 is being actively exploited in the wild, with observed activity dating back to May 7, 2026 and an increase in early June. The vendor characterizes the campaign as limited in scope, affecting several dozen organizations. At least one incident has been linked to a Qilin ransomware affiliate, which Check Point assesses with medium confidence. Rapid7 has observed at least one case with high confidence that can be attributed to CVE-2026-50751.Separately, during its investigation Check Point identified a related vulnerability, CVE-2026-50752 (CVSS 7.4), in the same IKEv1 code path that could enable a man-in-the-middle attack against site-to-site VPN tunnels under certain configurations. No exploitation of CVE-2026-50752 has been observed.Check Point VPN products have been targeted by zero-day vulnerabilities in the past. In May 2024, CVE-2024-24919, a high-severity information disclosure vulnerability in Check Point Quantum Security Gateways, was exploited in the wild and subsequently added to the CISA Known Exploited...
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2024-09-29 08:20:56 UTC · 6 stars
PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing server responses
github · Created 2024-06-10 01:29:19 UTC · 2 stars
Python script to automate the process of finding vulnerable sites for CVE-2024-24919.
github · Created 2024-06-09 06:54:51 UTC · 9 stars
POC - CVE-2024–24919 - Check Point Security Gateways
github · Created 2024-06-03 18:17:45 UTC · 5 stars
Nmap script to check vulnerability CVE-2024-24919
github · Created 2024-06-03 13:30:31 UTC · 6 stars
github · Created 2024-06-03 12:18:35 UTC · 3 stars
CVE-2024-24919 Exploit and PoC - Critical LFI for Remote Access VPN or Mobile Access.
github · Created 2024-06-02 20:16:22 UTC · 2 stars
CVE-2024-24919 Sniper - A powerful tool for scanning Check Point Security Gateway CVE-2024-24919 vulnerability. Supports single & bulk scanning, multithreading, and generates detailed CSV reports. Ideal for penetration testers and security researchers.
github · Created 2024-06-01 12:02:43 UTC · 2 stars
Herramienta de explotación para explotar la vulnerabilidad CVE-2024-24919 en las VPN de Checkpoint Firewall
github · Created 2024-06-01 10:51:14 UTC · 31 stars
CVE-2024-24919 [Check Point Security Gateway Information Disclosure]
github · Created 2024-05-31 18:14:19 UTC · 16 stars
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-24919, a critical vulnerability discovered in Check Point SVN. The vulnerability allows for reading system files. CVE ID: CVE-2024-24919
github · Created 2024-05-31 17:14:48 UTC · 3 stars
Exploit tool to validate CVE-2024-24919 vulnerability on Checkpoint Firewall VPNs
github · Created 2024-05-31 13:11:40 UTC · 17 stars
CVE-2024-24919 exploit
github · Created 2024-05-31 12:33:34 UTC · 4 stars
Nuclei template for CVE-2024-24919
github · Created 2024-05-31 11:52:59 UTC · 49 stars
github · Created 2024-05-31 10:18:36 UTC · 23 stars
An Vulnerability detection and Exploitation tool for CVE-2024-24919
github · Created 2024-05-31 07:59:17 UTC · 3 stars
Simple POC Python script that check & leverage Check Point CVE-2024-24919 vulnerability (Wrong Check Point)
github · Created 2024-05-30 20:14:19 UTC · 3 stars
Quick and simple script that takes as input a file with multiple URLs to check for the CVE-2024-24919 vulnerability in CHECKPOINT
github · Created 2024-05-30 16:23:18 UTC · 13 stars
CVE-2024-24919 Exploit PoC
github · Created 2024-05-30 14:41:32 UTC · 5 stars
POC exploit for CVE-2024-24919 information leakage
github · Created 2024-05-30 07:55:53 UTC · 6 stars
Nuclei Template to discover CVE-2024-24919. A path traversal vulnerability in CheckPoint SSLVPN.
nuclei · Created Unknown
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
19:21 UTC about 1 month ago19:21 UTC · about 1 month ago
KEV confirmed by Rapid7
Exploitation attested by an external source
-
00:00 UTC about 2 months ago00:00 UTC · about 2 months ago
KEV confirmed by The Shadowserver
Exploitation attested by an external source
-
00:00 UTC about 1 year ago00:00 UTC · about 1 year ago
Nuclei template available
Scanner coverage available
-
20:07 UTC about 2 years ago20:07 UTC · about 2 years ago
Nessus plugin available
Scanner coverage available
-
07:55 UTC about 2 years ago07:55 UTC · about 2 years ago
Public PoC available
Public proof-of-concept code published
-
00:00 UTC about 2 years ago00:00 UTC · about 2 years ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
00:00 UTC about 2 years ago00:00 UTC · about 2 years ago
Used in qilin ransomware malware
Exploit observed in malware
-
18:22 UTC about 2 years ago18:22 UTC · about 2 years ago
CVE published
Vulnerability disclosed publicly
-
15:19 UTC over 2 years ago15:19 UTC · over 2 years ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2024-24919
{
"cve_id": "CVE-2024-24919",
"title": "Information disclosure",
"affected_vendor": "checkpoint",
"affected_product": "Check Point Quantum Gateway, Spark Gateway and CloudGuard Network",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 8.6,
"epss_score": 0.99978,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}