logo

The Global Impact of CVE-2024-24919 in CheckPoint VPN Gateways

ID: 0c3675a7-4279-5c9b-9135-ec448ed9c666

STIX ID: report--0c3675a7-4279-5c9b-9135-ec448ed9c666

Feed Name: Censys Blog

Threat Score
78/100

Date Published: 2024-06-05

Date Updated: 2026-04-27

Author: Jean Pierre Ruiz Ocampo; The Censys Research Team

...
...

Censys analyzed CVE-2024-24919 — a critical zero-day arbitrary file read vulnerability affecting various Check Point VPN gateway products — reporting 13,754 Censys-visible exposed hosts as of June 3, 2024. The report highlights that the vulnerability is actively exploited, provides geographic and ASN exposure breakdowns (notably ~6,000 hosts in Japan and large counts on NTT networks), identifies ~554 potentially vulnerable Quantum Spark instances and 227 patched instances, notes that exploitation requires specific blades (IPSec VPN or Mobile Access) and may not yield full compromise, and lists Check Point patch versions and Censys queries to locate affected devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.