← Vulnerability feed

Vulnerability record · CVE-2024-24919 · published 28 May 2024

CVE-2024-24919: Check Point Security Gateway information disclosure via remote access VPN

Checkpoint · Quantum Spark Firmware

Check Point Security Gateways with Remote Access VPN or Mobile Access Software Blades enabled expose information to an unauthenticated attacker reachable over the internet. The flaw is an information exposure issue (CWE-200) that can leak sensitive data from the gateway. A vendor security fix is available.

8.6 CVSS 3.1 High CISA KEV since 30 May 2024 Known ransomware use EPSS 100% · top 0.1% CWE-200 · Information exposure
8.6CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
4References
5 Aug 2026Last modified by NVD

Description

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: medium.

critical priorityIt is in CISA KEV with known ransomware campaign use, has an EPSS probability near 1.0, and is remotely exploitable without authentication.

What it is

Check Point Security Gateways with Remote Access VPN or Mobile Access Software Blades enabled expose information to an unauthenticated attacker reachable over the internet. The flaw is an information exposure issue (CWE-200) that can leak sensitive data from the gateway. A vendor security fix is available.

Impact

An attacker can read certain information on the affected gateway without authentication. Because the record does not specify which data is exposed, the exact confidentiality loss beyond 'certain information' cannot be determined from this record.

Attack surface

Reached over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any internet-exposed gateway with Remote Access VPN or Mobile Access Software Blades enabled is a candidate. No authentication is required.

Exploitation

CISA added it to KEV on 2024-05-30 with a 2024-06-20 due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99978 (percentile 0.99979), indicating active exploitation.

What to do

  • Apply the Check Point security fix referenced in vendor advisory sk182336 as the first action.
  • If patching cannot be completed immediately, follow the vendor mitigation steps in sk182336 or discontinue use of the affected product per CISA guidance.
  • Restrict internet exposure of Remote Access VPN and Mobile Access Software Blades where operationally possible.
  • Review gateway logs and configurations for signs of prior access before patching.
  • Track the CISA KEV due date of 2024-06-20 for remediation compliance.

Detection

  • Hunt gateway and VPN logs for unauthenticated or anomalous access attempts against Remote Access VPN or Mobile Access endpoints.
  • Monitor for unusual outbound connections or data retrieval patterns from Security Gateway management interfaces.
  • Correlate gateway access events with ransomware-related indicators given the KEV ransomware flag.
  • Alert on exploitation attempts matching public reporting for CVE-2024-24919 against exposed Check Point gateways.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-24919 to the Known Exploited Vulnerabilities catalog on 30 May 2024 as "Check Point Quantum Security Gateways Information Disclosure Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 20 June 2024.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-24919 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.9CVE-2021-3449OpenSSL TLS server NULL pointer dereference via renegotiation ClientHelloAn OpenSSL TLS server can be crashed by a maliciously crafted TLSv1.2 renegotiation ClientHello that omits the signature_algorithms extension while i…EPSS 64%analysed5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed7.5CVE-2026-20133Cisco Catalyst SD-WAN Manager insufficient file system restrictions expose dataCisco Catalyst SD-WAN Software has insufficient file system restrictions that let an attacker read sensitive files on the underlying operating system…KEVEPSS 32%analysed7.5CVE-2025-31125Vite dev server improper access control exposes arbitrary filesVite's dev server fails to restrict file access when a request uses the ?inline&import or ?raw?import query patterns, allowing content of files that …KEVEPSS 65%analysed5.5CVE-2026-20805Windows Desktop Window Manager information disclosureDesktop Windows Manager (DWM) in Microsoft Windows exposes sensitive information to an unauthorized actor, allowing a local attacker with existing ac…KEVEPSS 7.2%analysed7.5CVE-2021-41277Metabase custom GeoJSON map feature allows local file inclusionMetabase does not validate URLs supplied through the custom GeoJSON map setting (admin->settings->maps->custom maps->add a map) before loading them. …KEVEPSS 97%analysed5.5CVE-2023-21237Android notification UI flaw hides foreground service alertsIn applyRemoteView of NotificationContentInflater.java, Android 13 mishandles notification UI so a foreground service notification can be hidden. The…KEVEPSS 0.27%analysed7.5CVE-2020-3259Cisco ASA and FTD web services memory disclosure via crafted URLCisco ASA and FTD web services interfaces mishandle buffer tracking when parsing invalid URLs, allowing memory contents to be read. The flaw affects …KEVEPSS 72%analysed

Source: NIST National Vulnerability Database (record CVE-2024-24919), CISA KEV, FIRST EPSS (scores of 2026-09-18). This page is refreshed as NVD updates the record.