CVE ID
CVE-2024-24919
Vulnerability Name
Check Point Quantum Security Gateways Information Disclosure Vulnerability
- Project: Check Point
- Product: Quantum Security Gateways
Date
- Date Added: 2024-05-30
- Due Date: 2024-06-20
Description
Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances.
Known To Be Used in Ransomware Campaigns?
Known
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://support.checkpoint.com/results/sk/sk182336 ; https://nvd.nist.gov/vuln/detail/CVE-2024-24919
Related Security News
- Chinese Hackers RedNovember Target Global Governments Using Pantegana and Cobalt Strike
- China-Linked Attackers Exploit Check Point Flaw to Deploy ShadowPad and Ransomware
- New NailaoLocker ransomware used against EU healthcare orgs
- Chinese Hackers Exploit Visual Studio Code in Southeast Asian Cyberattacks
- U.S. Agencies Warn of Iranian Hacking Group's Ongoing Ransomware Attacks
- Iranian hackers work with ransomware gangs to extort breached orgs
- CISA warns of actively exploited Linux privilege elevation flaw
- Check Point VPN zero-day exploited since beginning of April (CVE-2024-24919)
- Check Point VPN zero-day exploited in attacks since April 30
- Check Point releases emergency fix for VPN zero-day exploited in attacks
Top comments (0)