LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-24919: Check Point Quantum Security Gateways Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 30, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 20, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-24919 to its Known Exploited Vulnerabilities catalog on May 30, 2024, with a federal patch deadline of Jun 20, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the…

CVE-2024-24919 is an information disclosure vulnerability in Check Point Quantum Security Gateways. It can allow an attacker to access information on gateways that are connected to the internet when IPSec VPN, Remote Access VPN, or Mobile Access is enabled. The issue also affects related product lines including CloudGuard Network, Quantum Scalable Chassis, and Quantum Spark Appliances. This matters because the vulnerability has been used in ransomware activity, and internet-facing gateways with those features present a direct path for unauthorized information access.

Defenders should treat any internet-reachable Check Point gateway with the listed VPN or Mobile Access features as potentially exposed until the vendor mitigations are confirmed and applied. Specifics such as exact affected builds must be verified against the vendor advisory.

How it works

The flaw is classified as CWE-200 (information exposure). Public detail describes an unspecified information disclosure vulnerability that potentially lets an attacker retrieve information from affected gateways. Exploitation requires the gateway to be reachable from the internet and to have IPSec VPN, Remote Access VPN, or Mobile Access enabled. No further exploit mechanics are provided in the available summary, so teams should not assume particular request formats or payloads; instead treat any unauthenticated or unexpected access to gateway information endpoints as suspicious and confirm behavior against the vendor advisory.

Because the vulnerability is information disclosure rather than remote code execution, the immediate risk is leakage of data that could aid further attacks, credential harvesting, or reconnaissance. The fact that it has been observed in ransomware campaigns elevates the priority for any organization running the affected configurations.

Am I affected? How to find it in your systems

Check Point Quantum Security Gateways and the related lines (CloudGuard Network, Quantum Scalable Chassis, Quantum Spark Appliances) are typically deployed as perimeter or data-center firewalls and VPN concentrators. Inventory every Check Point appliance or virtual instance that terminates VPN or Mobile Access traffic and is reachable from the public internet.

Because exact version ranges are not listed here, compare every discovered device against the vendor advisory to determine whether it is in scope. Devices that are not internet-connected or that have the listed features disabled are lower risk but should still be inventoried.

How to remediate

The primary action is to apply the mitigations or updates published by Check Point for CVE-2024-24919. Follow the vendor instructions exactly; if mitigations are unavailable for a given product, the required action is to discontinue use of that product until a fix is available. After applying the vendor guidance, re-verify that the affected features no longer expose information and that the devices remain functional for legitimate VPN and Mobile Access traffic.

As part of remediation hygiene for this class of issue, restrict management and VPN listener interfaces to trusted networks where possible, enforce strong authentication on all remote-access services, and ensure logging of access attempts is enabled and forwarded to a central SIEM. Confirm the final configuration state against the vendor advisory rather than relying on generic assumptions.

If you can't patch immediately

Until the vendor mitigations can be applied, reduce exposure with compensating controls:

These steps do not replace the vendor fix; they only lower risk while the official remediation is prepared and tested.

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to breaches and ransomware incidents. If your Check Point gateways were internet-facing with the affected features enabled, assume that information may have been accessed and treat the event as a potential incident. Review logs for signs of unauthorized access, rotate any credentials or secrets that could have been exposed, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data to determine whether related accounts appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCheck Point · Quantum Security Gateways
WeaknessCWE-200
Added to CISA KEVMay 30, 2024
Federal patch deadlineJun 20, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities