CVE-2024-24919 - Check Point Quantum Security Gateways Information Disclosure Vulnerability
Project:Check Point
Product:Quantum Security Gateways
Date Added:2024-05-30Due Date:2024-06-20
Vulnerability Name
Check Point Quantum Security Gateways Information Disclosure Vulnerability
Description
Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.
Known To Be Used in Ransomware Campaigns?
Known
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://support.checkpoint.com/results/sk/sk182336
https://nvd.nist.gov/vuln/detail/CVE-2024-24919
Related News Articles
China-Linked Attackers Exploit Check Point Flaw to Deploy ShadowPad and RansomwareFebruary 20, 2025
New NailaoLocker ransomware used against EU healthcare orgsFebruary 20, 2025
Chinese Hackers Exploit Visual Studio Code in Southeast Asian CyberattacksSeptember 9, 2024
U.S. Agencies Warn of Iranian Hacking Group's Ongoing Ransomware AttacksAugust 29, 2024
Iranian hackers work with ransomware gangs to extort breached orgsAugust 29, 2024