CVE-2024-24919:CVE-2024-24919 is an information disclosure vulnerability affecting Check Point Quantum Gateway, Spark Gateway, and CloudGuard Network products, which may allow an attacker to read sensitive information when connected to the internet with remote Access VPN or Mobile Access Software Blades enabled.

splash
Back

Description Preview

CVE-2024-24919 is a vulnerability identified in Check Point's security products, specifically the Quantum Gateway, Spark Gateway, and CloudGuard Network. The vulnerability arises from improper handling of sensitive information, potentially allowing unauthorized actors to access certain data once the affected devices are connected to the internet and have remote Access VPN or Mobile Access Software Blades enabled. A security fix has been released to mitigate this vulnerability, and users are strongly advised to apply the necessary updates to protect their systems.

Overview

  • CVE ID: CVE-2024-24919
  • Vendor: Check Point
  • Affected Products:
    • Check Point Quantum Gateway and CloudGuard Network versions R81.20, R81.10, R81, R80.40
    • Check Point Spark versions R81.10, R80.20
  • Vulnerability Type: Information Disclosure
  • CWE Classification: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • CVSS Score: 8.6 (High)
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

Remediation

Check Point has released a security fix to address CVE-2024-24919. Users of the affected products are advised to update their systems to the latest versions as specified by Check Point. Detailed instructions for applying the security fix can be found in the official support documentation linked below.

References

Early Warning

Customers using Armis Early Warning were notified about this vulnerability before it appeared in CISA's Known Exploited Vulnerabilities Catalog, enabling them to assess their exposure and act proactively. Armis offers these examples of CVEs already included in CISA KEV for potential customers. Click here to learn how to receive alerts earlier.

Armis Alert Date
May 28, 2024
CISA KEV Date
May 30, 2024
2days early

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Professional, Scientific, & Technical Services: Low
    Professional, Scientific, & Technical Services
  2. Finance and Insurance: Low
    Finance and Insurance
  3. Accommodation & Food Services: Low
    Accommodation & Food Services
  4. Administrative, Support, Waste Management & Remediation Services: Low
    Administrative, Support, Waste Management & Remediation Services
  5. Agriculture, Forestry Fishing & Hunting: Low
    Agriculture, Forestry Fishing & Hunting
  6. Arts, Entertainment & Recreation: Low
    Arts, Entertainment & Recreation
  7. Construction: Low
    Construction
  8. Educational Services: Low
    Educational Services
  9. Health Care & Social Assistance: Low
    Health Care & Social Assistance
  10. Information: Low
    Information
  11. Management of Companies & Enterprises: Low
    Management of Companies & Enterprises
  12. Manufacturing: Low
    Manufacturing
  13. Mining: Low
    Mining
  14. Other Services (except Public Administration): Low
    Other Services (except Public Administration)
  15. Public Administration: Low
    Public Administration
  16. Real Estate Rental & Leasing: Low
    Real Estate Rental & Leasing
  17. Retail Trade: Low
    Retail Trade
  18. Transportation & Warehousing: Low
    Transportation & Warehousing
  19. Utilities: Low
    Utilities
  20. Wholesale Trade: Low
    Wholesale Trade

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background