Skip to content
COOEY

EXPOSURES › CVE-2024-24919

CVE-2024-24919

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-05-30 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-24919 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatched

Check Point Quantum Security Gateways suffered an information disclosure vulnerability actively exploited in the wild, allowing attackers to access data on gateways with VPN enabled.

An information disclosure flaw in Check Point Quantum Security Gateways was actively exploited in the wild, enabling attackers to access sensitive data on gateways with IPSec, Remote Access, or Mobile Access VPN enabled. This failure is critical for DIB organizations relying on Check Point for network security, as it directly violates the principle of least privilege and exposes data in transit. Organizations must immediately patch this CVE and review their VPN configurations to ensure no unpatched gateways remain exposed to the internet.

Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating a severe, avoidable failure where a known or easily discoverable flaw was left unpatched long enough for attackers to weaponize it for data theft.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.