CyberzSOC

Publication detail
← Back to advisories & guidance

2024-053: Zero-day Vulnerability in Check Point Security Gateways ↗ source

May 30, 2024 CERT-EU Advisory

Summary

This high-severity information disclosure vulnerability can be exploited to gain unauthorised access to sensitive information on systems with remote Access VPN or Mobile Access Software Blades enabled [1]. It is recommended applying the hotfix and the extra protection measures provided by the vendor Tracked as CVE-2024-24919, the high-severity information disclosure vulnerability enables attackers to read certain information on internet-exposed Check Point Security Gateways with remote Access VPN or Mobile Access Software Blades enabled [1]. Check Point has released the following security updates to address the flaw [1]: CERT-EU recommends applying the hotfix and the extra protection measures on affected devices As described in Check Point’s advisory, it is strongly recommended [2]: Upon taking these actions, it is also recommended reviewing the authentication logs for those local accounts to identify any suspicious connection.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-24919 8.6 High Check Point Quantum Security Gateways Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker t…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.