CVE-2024-24919
checkpoint Check Point Quantum Gateway, Spark Gateway and CloudGuard Network, checkpoint quantum_security_gateway_firmware, checkpoint cloudguard_network
Published 28 May 2024 · updated 5 Aug 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 30 May 2024, with a remediation deadline of 20 Jun 2024 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
References
- support.checkpoint.com/results/sk/sk182336 · Mitigation, Patch, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-24919 · US Government Resource
- www.mnemonic.io/resources/blog/advisory-check-point-remote-access-vpn-vulnerability-cve-2024-24919/ · Third Party Advisory