FLASH Alert - Information Disclosure vulnerability in Check Point’s Quantum Gateway
SOS Intelligence
Dark Web Monitoring toolkit for business and enterprise. Managed Threat Intelligence services and data-breach alerts.
Hello there,
CVSS 7.5 HIGH (Provisional)
On 27 May 2024, Check Point disclosed a vulnerability impacting the following products:
CVE-2024-24919 is an information disclosure vulnerability which would allow an unauthenticated threat actor to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades.
The following versions are known to be affected:
The vulnerability is exploitable on affected systems if ONE of the following conditions is met:
Check Point has issued detailed instructions for applying hotfixes to affected services to mitigate this vulnerability.? Additionally, The following has also been recommended:
The announcement of this vulnerability comes after Check Point identified a small number of login attempts on older local VPN accounts that used an unrecommended password-only authentication method.? This indicates that the vulnerability is being exploited in the wild, and so the recommended hotfixes should be applied as soon as practicable.
Stay safe,
Daniel Collyer
Threat Intelligence Analyst
SOS Intelligence