Check Point Security Gateway Information Disclosure Vulnerability (CVE-2024-24919)
ID: 563581af-a504-57e9-94cc-478b9124a5dd
STIX ID: report--563581af-a504-57e9-94cc-478b9124a5dd
Feed Name: Qualys Blog
Check Point published a zero-day advisory for CVE-2024-24919 (CVSS 8.6) describing an unauthenticated remote file-read vulnerability in multiple Check Point appliances (CloudGuard, Quantum Maestro, Quantum Security Gateways, Quantum Spark) that is being actively exploited and listed in CISA’s KEV catalog; Qualys released QID 150947 to detect vulnerable hosts and Check Point has published patches and updates for affected versions. The issue permits attackers to read sensitive files (example: /etc/passwd) on gateways with IPsec VPN, Remote Access, or Mobile Access blades enabled, though exploitation requires specific configurations and exposed password files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
