CVE-2024-24919

Information disclosure

Severity
High 8.6
CVSS 3.1
Exploited
Yes — in CISA KEV
Added May 30, 2024 · known ransomware use
EPSS
1.000
100.0th percentile
Discovered by
Not disclosed
Published
May 28, 2024
Assigned by checkpoint

Description

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

Weakness: CWE-200

Affected products

Vendor Product Category Matched by
Check Point CloudGuard Cloud Security cna-assigner
Check Point Quantum Security Gateway Firewall / NGFW cna-assigner
Check Point Quantum Spark Firewall / NGFW cna-assigner
Vendor-reported products (13)
  • checkpoint · Check Point Quantum Gateway, Spark Gateway and CloudGuard Network
  • checkpoint · quantum_security_gateway_firmware
  • checkpoint · quantum_security_gateway_firmware
  • checkpoint · quantum_security_gateway_firmware
  • checkpoint · quantum_security_gateway_firmware
  • checkpoint · cloudguard_network
  • checkpoint · cloudguard_network
  • checkpoint · cloudguard_network
  • checkpoint · cloudguard_network
  • checkpoint · quantum_spark_appliances
  • checkpoint · quantum_spark_appliances
  • checkpoint · quantum_spark_appliances
  • checkpoint · quantum_spark_appliances

Something wrong here?