Vulnerability record · CVE-2024-24919 · published 28 May 2024
CVE-2024-24919: Check Point Security Gateway information disclosure via remote access VPN
Checkpoint · Quantum Spark Firmware
Check Point Security Gateways with Remote Access VPN or Mobile Access Software Blades enabled expose information to an unauthenticated attacker reachable over the internet. The flaw is an information exposure issue (CWE-200) that can leak sensitive data from the gateway. A vendor security fix is available.
Description
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with known ransomware campaign use, has an EPSS probability near 1.0, and is remotely exploitable without authentication.
What it is
Check Point Security Gateways with Remote Access VPN or Mobile Access Software Blades enabled expose information to an unauthenticated attacker reachable over the internet. The flaw is an information exposure issue (CWE-200) that can leak sensitive data from the gateway. A vendor security fix is available.
Impact
An attacker can read certain information on the affected gateway without authentication. Because the record does not specify which data is exposed, the exact confidentiality loss beyond 'certain information' cannot be determined from this record.
Attack surface
Reached over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any internet-exposed gateway with Remote Access VPN or Mobile Access Software Blades enabled is a candidate. No authentication is required.
Exploitation
CISA added it to KEV on 2024-05-30 with a 2024-06-20 due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99978 (percentile 0.99979), indicating active exploitation.
What to do
- Apply the Check Point security fix referenced in vendor advisory sk182336 as the first action.
- If patching cannot be completed immediately, follow the vendor mitigation steps in sk182336 or discontinue use of the affected product per CISA guidance.
- Restrict internet exposure of Remote Access VPN and Mobile Access Software Blades where operationally possible.
- Review gateway logs and configurations for signs of prior access before patching.
- Track the CISA KEV due date of 2024-06-20 for remediation compliance.
Detection
- Hunt gateway and VPN logs for unauthenticated or anomalous access attempts against Remote Access VPN or Mobile Access endpoints.
- Monitor for unusual outbound connections or data retrieval patterns from Security Gateway management interfaces.
- Correlate gateway access events with ransomware-related indicators given the KEV ransomware flag.
- Alert on exploitation attempts matching public reporting for CVE-2024-24919 against exposed Check Point gateways.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-24919 to the Known Exploited Vulnerabilities catalog on 30 May 2024 as "Check Point Quantum Security Gateways Information Disclosure Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 20 June 2024.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.checkpoint.com/results/sk/sk182336 | MitigationPatchVendor Advisory |
| https://support.checkpoint.com/results/sk/sk182336 | MitigationPatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-24919 | US Government Resource |
| https://www.mnemonic.io/resources/blog/advisory-check-point-remote-access-vpn-vulnerability-cve-2024-24919/ | Third Party Advisory |
Track CVE-2024-24919 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-24919), CISA KEV, FIRST EPSS (scores of 2026-09-18). This page is refreshed as NVD updates the record.