logo

Check Point Security Gateway Information Disclosure Vulnerability (CVE-2024-24919)

ID: 563581af-a504-57e9-94cc-478b9124a5dd

STIX ID: report--563581af-a504-57e9-94cc-478b9124a5dd

Feed Name: Qualys Blog

Threat Score
82/100

Date Published: 2024-06-07

Date Updated: 2026-04-28

Author: Sheela Sarva

...
...

Check Point published a zero-day advisory for CVE-2024-24919 (CVSS 8.6) describing an unauthenticated remote file-read vulnerability in multiple Check Point appliances (CloudGuard, Quantum Maestro, Quantum Security Gateways, Quantum Spark) that is being actively exploited and listed in CISA’s KEV catalog; Qualys released QID 150947 to detect vulnerable hosts and Check Point has published patches and updates for affected versions. The issue permits attackers to read sensitive files (example: /etc/passwd) on gateways with IPsec VPN, Remote Access, or Mobile Access blades enabled, though exploitation requires specific configurations and exposed password files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.