CVE-2024-24919

checkpoint Check Point Quantum Gateway, Spark Gateway and CloudGuard Network, checkpoint quantum_security_gateway_firmware, checkpoint cloudguard_network

Published 28 May 2024 · updated 5 Aug 2026 · Analyzed

8.6 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 30 May 2024, with a remediation deadline of 20 Jun 2024 for US federal agencies. It has been used in ransomware campaigns.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

References